CVE-2025-62772 Details
Description
On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
A vulnerability exists in Mercku M6a devices running through version 2.1.0, where session tokens can remain valid for extended periods, in some cases, months. The authentication system generates predictable session tokens based on timestamps, allowing for brute-force attacks to hijack administrative sessions. This issue is compounded by a lack of rate limiting and secure cryptographic algorithms for session generation. Once administrative access is gained, a hidden telnet backdoor can be activated, leading to root privilege escalation and full control over the device.
Users are advised to implement proper CSRF protection, remove or secure hidden endpoints, use cryptographically secure session generation, enforce session expiration, and follow GPL requirements for OpenWrt modifications.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 22, 2025CISA-ADP
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.nullvoid.me/posts/mercku-exploits/ | [email protected] | ExploitRemedyTechnical Analysis |
| https://seclists.org/fulldisclosure/2025/Oct/10 | [email protected] | Mailing ListPartial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-305 | Authentication Bypass by Primary Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mercku M6a | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 22, 2025 | New CVE Received | [email protected] |
Volerion