CVE-2025-49198: Sick Media Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.

Affected products

  • Sick Media Server: any version

Published 2025-06-12. Last modified 2026-06-17.