CVE-2025-52689
CRITICALFirmware - Privilege Escalation
Title source: llmDescription
Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.0072
EPSS Percentile
72.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-384
Status
published
Products (5)
Alcatel-Lucent/OmniAccess Stellar Products
AP1100 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar Products
AP1200 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar Products
AP1300 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar Products
AP1400 AWOS versions 5.0.2 GA and earlier
Alcatel-Lucent/OmniAccess Stellar Products
AP1500 AWOS versions 5.0.2 GA and earlier
Published
Jul 16, 2025
Tracked Since
Feb 18, 2026