Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

DB Elettronica SFT DAB Series Session Management Vulnerability Allowing Unauthorized Account Deletion

Vulnerability

A session management vulnerability has been identified in the DB Elettronica SFT DAB series, specifically in version 1.9.3. This vulnerability allows attackers to bypass authentication by reusing session identifiers tied to IP addresses. Exploitation involves intercepting and reusing these session identifiers to access a vulnerable API, enabling unauthorized removal of user accounts.

Impact

Exploitation of this vulnerability leads to unauthorized account deletions on the affected device.

Reproduction

To reproduce this vulnerability, an established session must be intercepted and its session identifier reused. This can be done by waiting for a session to be established and then sending unauthorized requests to the vulnerable API endpoint 'userManager.cgx' to remove a user account.

Added: Dec 10, 2025, 9:31 PM
Updated: Dec 10, 2025, 9:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.0
remediation
0.0
relevance
1.3
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.