Session Management Vulnerability in OmniAccess Stellar by Alcatel-Lucent
CVE-2025-52689

9.8CRITICAL

Key Information:

Vendor
CVE Published:
16 July 2025

What is CVE-2025-52689?

The vulnerability allows an unauthenticated attacker to exploit a flaw in the session management of OmniAccess Stellar. By spoofing a login request, attackers can obtain a valid session ID with administrator privileges. This could enable them to manipulate the access point's behavior and potentially compromise the network, underscoring a significant threat to user security and privacy.

Affected Version(s)

OmniAccess Stellar Products AP1100 AWOS versions 5.0.2 GA and earlier

OmniAccess Stellar Products AP1200 AWOS versions 5.0.2 GA and earlier

OmniAccess Stellar Products AP1300 AWOS versions 5.0.2 GA and earlier

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lam Jun Rong
Cao Yitian
.
CVE-2025-52689 : Session Management Vulnerability in OmniAccess Stellar by Alcatel-Lucent