CVE-2025-27494
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 20
Summary
CVE-2025-27494 is a newly identified vulnerability that affects SiPass integrated AC5102 (ACC-G2) and SiPass integrated ACC-AP devices with versions below V6.4.9. The issue lies in the improper input sanitization for the pubkey endpoint of the REST API. This security flaw enables authenticated remote administrators to escalate their privileges by injecting arbitrary commands, which are subsequently executed with root privileges. This vulnerability poses a serious risk to the affected systems, and an immediate update to a secure version is recommended.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.