CVE-2019-25278: Iwt Facesentry Access Control System Firmware

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.

Affected products

  • Iwt Facesentry Access Control System Firmware: version 5.7.0 only; version 5.7.2 only; version 6.4.8 only

Published 2026-01-08. Last modified 2026-06-17.