CVE-2025-52687

LOW

Alcatel-Lucent OmniAccess Stellar <= 5.0.2 GA - Authenticated JavaScript Injection and Denial of Service

Title source: llm
STIX 2.1

Description

Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).

Scores

CVSS v3 2.4
EPSS 0.0023
EPSS Percentile 13.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (5)
Alcatel-Lucent/OmniAccess Stellar AP1100 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar AP1200 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar AP1300 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar AP1400 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar AP1500 AWOS versions 5.0.2 GA and earlier
Published Jul 16, 2025
Tracked Since Feb 18, 2026