Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Users are recommended to download and upgrade to COMMGR v2.10.0 or later.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11466 | Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code. |
Wed, 16 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Apr 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code. | |
| Title | COMMGR - Insufficient Randomization Authentication Bypass | |
| Weaknesses | CWE-338 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Deltaww
Published:
Updated: 2025-08-19T00:11:36.662Z
Reserved: 2025-04-10T06:21:03.795Z
Link: CVE-2025-3495
Updated: 2025-04-16T14:23:01.695Z
Status : Deferred
Published: 2025-04-16T03:15:17.530
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-3495
No data.
OpenCVE Enrichment
No data.
EUVD