CRITICAL🇵🇱 Wersja polska

CVE-2026-38968

CVSS 9.8pub. 2026-07-02upd. 2026-07-08

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Ntop Ntopng

    APP
    Ntop
    ≤ 6.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-12520HIGH8.1same product

An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is...

CVE-2017-7458HIGH7.5same product

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to...

CVE-2017-7459HIGH7.5same product

ntopng before 3.0 allows HTTP Response Splitting.

CVE-2017-5473HIGH8.8same product

Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the au...

CVE-2017-7416MEDIUM6.1same product

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.