9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.
Basic Information
ID
CVE-2025-52689
Source
CSA
Published
Jul 16, 2025 at 06:30
Modified
Jul 16, 2025 at 14:40
Affected Product
Vendor
Alcatel-Lucent
Product
OmniAccess Stellar Products
Version
AP1100 AWOS versions 5.0.2 GA and earlier
Affected Versions
Alcatel-Lucent OmniAccess Stellar Products AP1100 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1200 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1300 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1400 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1500 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1200 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1300 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1400 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent OmniAccess Stellar Products AP1500 AWOS versions 5.0.2 GA and earlier