jro.sg
https://jro.sg/CVEs/CVE-2025-52688 CVE-2025-52688
CRITICAL
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
Record summary
CVE-2025-52688 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.
Description
Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OmniAccess Stellar ProductsBrowse Alcatel-Lucent / OmniAccess Stellar ProductsDefault status: unknown | CVE List | AP1100 AWOS versions 5.0.2 GA and earlier | affected |
| AP1200 AWOS versions 5.0.2 GA and earlier | affected | ||
| AP1300 AWOS versions 5.0.2 GA and earlier | affected | ||
| AP1400 AWOS versions 5.0.2 GA and earlier | affected | ||
| AP1500 AWOS versions 5.0.2 GA and earlier | affected |
Proofs of concept
1Repository PoCs
GitHubjoelczk/CVE-2025-52688Repository PoCby joelczkStars: 2Not analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-52688 al-enterprise.com
https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf csa.gov.sg
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072