CVE-2025-52688
Unauthenticated root command injection in access point (CVE-2025-52688)
CVE-2025-52688 is an operating-system command injection flaw (CWE-77) in an access point, rated CVSS 3.1 9.8 (critical). Its network vector (AV:N/AC:L/PR:N/UI:N) means a remote, unauthenticated attacker can trigger it with crafted input sent to the device over the network, with no user interaction and low attack complexity. Successful exploitation lets the attacker inject commands that run with root privileges on the access point, yielding loss of confidentiality, integrity, and availability and effectively full control of the device. Affected parties are organizations or individuals running the vulnerable access point; the specific vendor, model(s), and firmware version ranges must be confirmed from the assigned CNA's advisory, as they are not enumerated in the source data. Exploitation is not currently known in the wild and no public PoC exists, but EPSS assigns a 25.9% probability of exploitation within 30 days (98th percentile), indicating elevated near-term risk.
What to do: Consult the CNA's advisory for the affected access point models and firmware ranges and deploy the fixed firmware as soon as it is published; until then, restrict the device's management and exposed interfaces to trusted networks via ACLs or VPN and avoid internet-exposing the AP. Given the elevated EPSS (26% within 30 days), add this CVE to monitoring/watchlists and prioritize patching of internet-facing units. Do not rely on network segmentation alone as a fix — firmware remediation is required to close the root-level command injection.
| Access point (specific model(s) per CNA advisory) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.