Cacheable SSL Page Vulnerability in HCL AION Software
CVE-2025-52625

3.7LOW

Key Information:

Status
Vendor
CVE Published:
10 October 2025

What is CVE-2025-52625?

A vulnerability has been identified in HCL AION where cached SSL pages may lead to the exposure of sensitive information, such as user credentials, system identifiers, or internal file paths. This can potentially allow attackers with access to a device or browser to retrieve critical data, posing a significant security risk. It is crucial for users of AION version 2.0 to evaluate their security practices and ensure sensitive data is adequately protected against unauthorized access.

Affected Version(s)

AION 2.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52625 : Cacheable SSL Page Vulnerability in HCL AION Software