VYPR
High severity8.6NVD Advisory· Published Oct 27, 2025· Updated Jun 17, 2026

CVE-2025-60425

CVE-2025-60425

Description

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Nagios/Fusion4 versions
    cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:nagios:fusion:2024:r1.2:*:*:*:*:*:*
    • cpe:2.3:a:nagios:fusion:2024:r2.1:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: v2024R1.2, v2024R2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.