Junglewise Threat Intelligence

CVE-2025-25613: FS Inc S3150-8T2F cleartext credential transmission in web interface

CVE-2025-25613 · Severity: high · CVSS 7.5 · Published 2025-11-20

Executive brief

A vulnerability in FS Inc S3150-8T2F network switches allows for the exposure of administrative credentials. The device's web management interface transmits usernames and passwords in an insecure, easily reversible format during every administrative action. An attacker monitoring network traffic could capture these credentials to take full control of the switch, potentially leading to network redirection or unauthorized access to corporate data.

Technical details

The FS Inc S3150-8T2F L2+ switch (running VxWorks RTOS) suffers from insecure storage and transmission of sensitive information (CWE-312). The web-based administrative application includes the user's plaintext username and password within HTTP cookies for every POST request made to the server. While the data is Base64 encoded, this provides no cryptographic security and is trivial to decode. A network-positioned attacker (via man-in-the-middle or traffic sniffing) can intercept these cookies to obtain full administrative credentials. The issue is addressed in firmware version 2.2.0D Build 135103.

Affected products

  • FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch All versions before 2.2.0D Build 135103

Timeline

  • 2025-11-20: advisory: Initial disclosure of CVE-2025-25613
  • 2025-11-20: patched: Firmware version 2.2.0D Build 135103 released to address the issue

References