Unrestricted File Upload Vulnerability in HCL AION
CVE-2025-55251

3.1LOW

Key Information:

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2025-55251?

HCL AION is vulnerable to an unrestricted file upload issue, allowing attackers to upload malicious files to the server without proper validation. This flaw can potentially lead to unauthorized code execution or compromise of the system, exposing sensitive data and undermining security protocols.

Affected Version(s)

AION 2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.