Unrated severityNVD Advisory· Published Jan 7, 2026· Updated Feb 18, 2026
FaceSentry Access Control System 6.4.8 Authentication Credentials MiTM Disclosure
CVE-2019-25278
Description
FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.
Affected products
2- Range: =6.4.8
- iWT Ltd./FaceSentry Access Control Systemv5Range: 6.4.8 build 264
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/153498mitreexploit
- www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5528.phpmitrethird-party-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/163192mitrevdb-entry
News mentions
0No linked articles in our index yet.