CVE-2025-52606

MEDIUM

HCL iControl - Weak Input Validation

Title source: manual
STIX 2.1

Description

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 6.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (2)
HCL/iControl 4.0.0
hcltech/icontrol 4.0.0
Published Jun 04, 2026
Tracked Since Jun 04, 2026