CVE Feed

    Dashboard / CVE / CVE-2025-63226

    CVE-2025-63226

    The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

    Published:Nov 18, 2025
    Last Modified:Feb 13, 2026
    EPS:Nov 18, 2025
    EPSS Score:0.00038
    CVSS Score:5.7

    Affected Products

    Vendor
    Sencore
    Product
    Decoder-ccv2
    Vendor
    Sencore
    Product
    Decoder-ccv2 Firmware
    Vendor
    Sencore
    Product
    En2sdi-2hd
    Vendor
    Sencore
    Product
    En2sdi-2hd Firmware
    Vendor
    Sencore
    Product
    Smp100
    Vendor
    Sencore
    Product
    Smp100 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High