« Volver al listado

CVE-2025-52687

Estado: AplazadaBaja (2.4)—

Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-52687",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-52687",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-16T14:37:22.658130Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.4,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
      "affectedData": [
        {
          "vendor": "Alcatel-Lucent",
          "product": "OmniAccess Stellar",
          "versions": [
            {
              "status": "affected",
              "version": "AP1100 AWOS versions 5.0.2 GA and earlier"
            },
            {
              "status": "affected",
              "version": "AP1200 AWOS versions 5.0.2 GA and earlier"
            },
            {
              "status": "affected",
              "version": "AP1300 AWOS versions 5.0.2 GA and earlier"
            },
            {
              "status": "affected",
              "version": "AP1400 AWOS versions 5.0.2 GA and earlier"
            },
            {
              "status": "affected",
              "version": "AP1500 AWOS versions 5.0.2 GA and earlier"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-07-16T07:15:21.683",
  "references": [
    {
      "url": "https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf",
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
    },
    {
      "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/",
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS)."
    },
    {
      "lang": "es",
      "value": "La explotación exitosa de esta vulnerabilidad podría permitir a un atacante con credenciales de administrador para el punto de acceso inyectar JavaScript malicioso en el payload del tráfico web, lo que podría conducir al secuestro de sesiones y a la denegación de servicio (DoS)."
    }
  ],
  "lastModified": "2026-06-17T09:36:54.310",
  "sourceIdentifier": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}