Session Management Vulnerability in OmniAccess Stellar by Alcatel-Lucent
CVE-2025-52689
9.8CRITICAL
What is CVE-2025-52689?
The vulnerability allows an unauthenticated attacker to exploit a flaw in the session management of OmniAccess Stellar. By spoofing a login request, attackers can obtain a valid session ID with administrator privileges. This could enable them to manipulate the access point's behavior and potentially compromise the network, underscoring a significant threat to user security and privacy.
Affected Version(s)
OmniAccess Stellar Products AP1100 AWOS versions 5.0.2 GA and earlier
OmniAccess Stellar Products AP1200 AWOS versions 5.0.2 GA and earlier
OmniAccess Stellar Products AP1300 AWOS versions 5.0.2 GA and earlier