Medium severity5.9NVD Advisory· Published Jan 8, 2026· Updated Jun 17, 2026
CVE-2019-25278
CVE-2019-25278
Description
FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:*
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.2:*:*:*:*:*:*:*
- cpe:2.3:o:iwt:facesentry_access_control_system_firmware:6.4.8:*:*:*:*:*:*:*
- Range: =6.4.8
- iWT Ltd./FaceSentry Access Control Systemv5Range: 6.4.8 build 264
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/153498nvdExploitThird Party Advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5528.phpnvdExploitThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/163192nvdThird Party Advisory
News mentions
0No linked articles in our index yet.