zum Inhalt springen

Failure to invalidate session tokens in AirServer Connect 3: an intercepted login token could be reused even after logout

Peripheral Devices

NTCF:
NTCF-2026-98789

Product:
Connect 3

Vendor:
AirServer

Criticality:
low

Status:
fixed

Discovered:
2026-06-29

Detail:
Public

Vulnerable version:
<=2026.03.13

Fixed version:
2026.09.29

Description

In accordance with the NTC Vulnerability Disclosure Policy, technical details of this vulnerability will not be publicly disclosed.

 

We recommend updating AirServer Connect 3 to the latest firmware version. We thank the AirServer team for their timely response and professionalism during the responsible disclosure process.

Timeline

2026-06-29: initial discovery

2026-07-02: first contact to vendor

2026-09-30: fix by vendor

2026-10-07: public disclosure