← Back to browse · API

CVE-2025-52689

Severity
CRITICAL
CVSS
9.8
EPSS
0.11542
Risk score
43.24
CISA KEV
No
PoC
No
Published
2025-07-16
Modified
2025-07-16
First seen
2026-08-07
Aliases
EUVD-2025-21586, GHSA-VV27-HW9X-F765
Products
Alcatel-Lucent:OmniAccess Stellar Products AP1100 AWOS versions 5.0.2 GA and earlier, Alcatel-Lucent:OmniAccess Stellar Products AP1200 AWOS versions 5.0.2 GA and earlier, Alcatel-Lucent:OmniAccess Stellar Products AP1300 AWOS versions 5.0.2 GA and earlier, Alcatel-Lucent:OmniAccess Stellar Products AP1400 AWOS versions 5.0.2 GA and earlier, Alcatel-Lucent:OmniAccess Stellar Products AP1500 AWOS versions 5.0.2 GA and earlier
Sources
euvd EUVD-2025-21586

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.

References