CVE-2025-49198: Sick Media Server
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
Affected products
- Sick Media Server: any version
Published 2025-06-12. Last modified 2026-06-17.