Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sencore decoder-ccv2
Sencore decoder-ccv2 Firmware Sencore en2sdi-2hd Sencore en2sdi-2hd Firmware Sencore smp100 Firmware |
|
| CPEs | cpe:2.3:h:sencore:decoder-ccv2:-:*:*:*:*:*:*:* cpe:2.3:h:sencore:en2sdi-2hd:-:*:*:*:*:*:*:* cpe:2.3:h:sencore:smp100:-:*:*:*:*:*:*:* cpe:2.3:o:sencore:decoder-ccv2_firmware:60.1.4:*:*:*:*:*:*:* cpe:2.3:o:sencore:en2sdi-2hd_firmware:60.1.29:*:*:*:*:*:*:* cpe:2.3:o:sencore:smp100_firmware:4.2.160:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sencore decoder-ccv2
Sencore decoder-ccv2 Firmware Sencore en2sdi-2hd Sencore en2sdi-2hd Firmware Sencore smp100 Firmware |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sencore
Sencore smp100 |
|
| Vendors & Products |
Sencore
Sencore smp100 |
Wed, 19 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-613 | |
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-19T18:52:23.807Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63226
Updated: 2025-11-19T18:51:35.570Z
Status : Analyzed
Published: 2025-11-18T20:15:47.583
Modified: 2026-02-13T16:13:55.730
Link: CVE-2025-63226
No data.
OpenCVE Enrichment
Updated: 2025-11-21T09:16:03Z