CVE-2025-15135: Improper Authentication in joey-zhou xiaozhi-esp32-server-java
A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file AuthenticationInterceptor.java of the component Cookie Handler. Executing manipulation can lead to improper authentication. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Upgrading to version 4.0.0 will fix this issue. It is recommended to upgrade the affected component.
CVE-2025-15135: Improper Authentication in joey-zhou xiaozhi-esp32-server-java
Description
A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file AuthenticationInterceptor.java of the component Cookie Handler. Executing manipulation can lead to improper authentication. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Upgrading to version 4.0.0 will fix this issue. It is recommended to upgrade the affected component.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-12-27T09:52:55.766Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6951204bd9131081aae4d832
Added to database: 12/28/2025, 12:19:23 PM
Last updated: 12/28/2025, 1:45:58 PM
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2025-15137: Command Injection in TRENDnet TEW-800MB
HighCVE-2025-15136: Command Injection in TRENDnet TEW-800MB
HighCVE-2025-15134: Cross Site Scripting in yourmaileyes MOOC
MediumCVE-2025-15110: Unrestricted Upload in jackq XCMS
MediumCVE-2025-15119: Improper Authorization in JeecgBoot
LowActions
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.