CVE-2025-27493

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 20

Summary

CVE-2025-27493 is a newly discovered vulnerability affecting SiPass integrated AC5102 (ACC-G2) and SiPass integrated ACC-AP devices with versions below V6.4.9. The issue lies in the improper sanitization of user input for specific commands on the telnet command line interface. An authenticated local administrator can exploit this vulnerability by injecting arbitrary commands, which are then executed with root privileges, enabling privilege escalation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share