CVE-2025-45814 Details
Description
Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack.
A session hijacking vulnerability has been identified in NOVELSAT's NS3000 version 8.1.1.125110, 7.2.8.124852, and 7.x, as well as in NS2000 version 7.02.08. The issue arises from missing authentication checks in the query.fcgi endpoint, allowing attackers to execute session hijacking attacks.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-45814 | [email protected] | ExploitThird Party Advisory |
| https://novelsat.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| novelsat ns3000 firmware | 7.2.8.124852 8.1.1.125110 |
CPE
Remediation
| |
| novelsat ns3000 | All versions |
CPE
Remediation
| |
| novelsat ns2000 firmware | 7.02.08 |
CPE
Remediation
| |
| novelsat ns2000 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Initial Analysis | [email protected] |
| Jul 2, 2025 | CVE Modified | CISA-ADP |
| Jul 2, 2025 | New CVE Received | [email protected] |