CVE-2025-15135

Source
https://cve.org/CVERecord?id=CVE-2025-15135
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15135.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15135
Published
2025-12-28T12:02:07.346Z
Modified
2026-08-12T03:51:21.943899885Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
joey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authentication
Details

A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file AuthenticationInterceptor.java of the component Cookie Handler. Executing manipulation can lead to improper authentication. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. Upgrading to version 4.0.0 will fix this issue. It is recommended to upgrade the affected component.

Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15135.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/joey-zhou/xiaozhi-esp32-server-java

Affected ranges

Type
GIT
Repo
https://github.com/joey-zhou/xiaozhi-esp32-server-java
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0"
        },
        {
            "last_affected": "3.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.0
v3.*
v3.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15135.json"