CVE-2025-59786
Cookies are not Invalidated upon Logout and Password Change
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
2N Telekomunikace a.s. · 2N Access CommanderWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →