CVE-2025-62309

LOW

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions.

Scores

CVSS v3 2.6
EPSS 0.0011
EPSS Percentile 1.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
HCL/AION 2.1.0
Published May 14, 2026
Tracked Since May 14, 2026