CVE-2025-25613
7.5FS Inc · S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch
The FS Inc S3150-8T2F switch transmits administrative session credentials in cleartext using base64 encoding within POST request cookies, allowing potential interception by unauthorized parties.
Executive summary
The FS Inc S3150-8T2F switch is vulnerable to sensitive information disclosure because it transmits administrative credentials in cleartext, posing a significant risk of unauthorized network access.
Vulnerability
This is a cleartext transmission of sensitive information vulnerability where the web-based administrative interface includes usernames and passwords in POST request cookies. The vulnerability is unauthenticated, as any actor with network access to the management interface can capture these credentials.
Business impact
The exposure of administrative credentials allows an attacker to gain full control over the network switch. Given the CVSS score of 7.5, this high-severity flaw could lead to complete compromise of network traffic, unauthorized configuration changes, or the facilitation of man-in-the-middle attacks, resulting in severe reputational and operational damage.
Remediation
Immediate Action: Upgrade the FS Inc S3150-8T2F switch firmware to version 2.2.0D Build 135103 or later to resolve the credential transmission flaw.
Proactive Monitoring: Monitor network traffic logs for unusual HTTP POST requests and review access logs for signs of unauthorized administrative authentication attempts.
Compensating Controls: Restrict access to the switch management interface to trusted management VLANs or specific IP addresses using an Access Control List (ACL) to prevent external exposure.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research wiki referenced by the CVE record.
Analyst recommendation
This vulnerability represents a critical security oversight that exposes administrative credentials to any observer on the local network. Administrators must prioritize the application of the vendor-provided firmware update to version 2.2.0D Build 135103 immediately. If patching is not immediately feasible, isolate the management interface from the production network to prevent potential credential theft.