CVE-2025-52688 Details
Description
Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.
A command injection vulnerability has been identified in the Alcatel OmniAccess Stellar AP1361D access point, specifically in the web management interface. This vulnerability arises because the web API does not properly sanitize usernames before incorporating them into system commands. As a result, an unauthenticated attacker can exploit this flaw to execute arbitrary commands with root privileges on the device. The issue was analyzed on firmware version 4.0.4, build 2046.
Alcatel recommends updating to the latest firmware version. For users unable to update, the workaround is to manage the access point using Enterprise Mode with the OmniVista Management platform and disable the web interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2025CISA-ADP
Assessed Jul 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jro.sg/CVEs/CVE-2025-52688/ | CISA-ADP | ExploitTechnical Analysis |
| https://jro.sg/CVEs/CVE-2025-52688/ | CSA | ExploitTechnical Analysis |
| https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf | CSA | AdvisoryBundleRemedyVendor |
| https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/ | CSA | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CSA |
Affected Products
| Product | Versions |
|---|---|
| Alcatel AP1361D | <= 4.0.4 (semver) |
CPE
Remediation
| |
| Alcatel OmniAccess Stellar AP1100 | All versions |
CPE
Remediation
| |
| Alcatel OmniAccess Stellar AP1200 | All versions |
CPE
Remediation
| |
| Alcatel OmniAccess Stellar AP1300 | All versions |
CPE
Remediation
| |
| Alcatel OmniAccess Stellar AP1400 | All versions |
CPE
Remediation
| |
| Alcatel OmniAccess Stellar AP1500 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CSA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | New CVE Received | CSA |
Volerion