CVE-2024-52285

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 306

Summary

CVE-2024-52285 is a newly identified vulnerability affecting SiPass integrated AC5102 (ACC-G2) and SiPass integrated ACC-AP devices with versions below V6.4.8. The issue lies in the exposure of Multicast QoS Telemetry Transport (MQTT) URLs without authentication. An unauthenticated remote attacker can exploit this vulnerability and gain access to sensitive data on the affected devices. This issue poses a significant risk, emphasizing the importance of updating these devices to the latest version to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share