COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.
History

Wed, 10 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Commax
Commax biometric Access Control System
Vendors & Products Commax
Commax biometric Access Control System

Wed, 10 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.
Title COMMAX Biometric Access Control System Authentication Bypass
Weaknesses CWE-565
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-09T20:37:44.232Z

Updated: 2025-12-10T15:39:38.212Z

Reserved: 2025-12-05T19:10:29.045Z

Link: CVE-2021-47706

cve-icon Vulnrichment

Updated: 2025-12-10T15:39:24.374Z

cve-icon NVD

Status : Received

Published: 2025-12-09T21:15:49.507

Modified: 2025-12-09T21:15:49.507

Link: CVE-2021-47706

cve-icon Redhat

No data.