CVE-2025-52687
Estado: AplazadaBaja (2.4)—
Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
- Puntuación base: 2.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CWE
- CWE-77
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-52687",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-52687",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-07-16T14:37:22.658130Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.4,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
"affectedData": [
{
"vendor": "Alcatel-Lucent",
"product": "OmniAccess Stellar",
"versions": [
{
"status": "affected",
"version": "AP1100 AWOS versions 5.0.2 GA and earlier"
},
{
"status": "affected",
"version": "AP1200 AWOS versions 5.0.2 GA and earlier"
},
{
"status": "affected",
"version": "AP1300 AWOS versions 5.0.2 GA and earlier"
},
{
"status": "affected",
"version": "AP1400 AWOS versions 5.0.2 GA and earlier"
},
{
"status": "affected",
"version": "AP1500 AWOS versions 5.0.2 GA and earlier"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-07-16T07:15:21.683",
"references": [
{
"url": "https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf",
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
},
{
"url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/",
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS)."
},
{
"lang": "es",
"value": "La explotación exitosa de esta vulnerabilidad podría permitir a un atacante con credenciales de administrador para el punto de acceso inyectar JavaScript malicioso en el payload del tráfico web, lo que podría conducir al secuestro de sesiones y a la denegación de servicio (DoS)."
}
],
"lastModified": "2026-06-17T09:36:54.310",
"sourceIdentifier": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}