7.6
/ 10
HIGH
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obtain network access. Client360 logs may display the client MAC as the username despite no MAC-authentication being enabled.
Basic Information
ID
CVE-2025-8679
Source
ExtremeNetworks
Published
Oct 1, 2025 at 17:19
Modified
Oct 1, 2025 at 17:29
Affected Product
Vendor
Extreme Networks
Product
ExtremeGuest Essentials
Version
25.4.0
Affected Versions
Extreme Networks ExtremeGuest Essentials 25.4.0