Mist offers wireless network management and cloud connectivity solutions, with the recurring vulnerability signal centered on application-layer and access-control flaws in its platform product. The observed weakness classes include code injection, cross-site scripting, cross-site request forgery, improper access control, and incorrect privilege assignment, reflecting the authentication and request-handling surface inherent to a cloud-based network management interface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mist over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5409CRITICAL A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py o | Jun 1, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-5411MEDIUM A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects the function tag_resources of the file src/mist/api/tag/views. | Jun 1, 2025 | 5.4 | 17 | NO | NO |
CVE-2025-5412MEDIUM A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function Login of the file src/mist/api/views.py of the component Au | Jun 2, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-5410MEDIUM A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the file src | Jun 1, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mist.
Media articles that mention a CVE ID that affects a product developed by Mist — matched by CVE ID, not by vendor name.