CVE-2025-52688 is a critical command injection vulnerability (CWE-77) affecting an unspecified access point product. With a CVSS score of 9.8, it allows unauthenticated attackers to execute commands with root privileges over the network, leading to complete compromise of the device. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, indicating no active exploitation. However, the vulnerability has garnered significant community discussion, with 10 mentions across platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Alcatel-Lucent | OmniAccess Stellar Products | AP1100 AWOS versions 5.0.2 GA and earlier, AP1200 AWOS versions 5.0.2 GA and earlier, AP1300 AWOS versions 5.0.2 GA and earlier, AP1400 AWOS versions 5.0.2 GA and earlier, AP1500 AWOS versions 5.0.2 GA and earlierCNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.