Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Wed, 16 Jul 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | JavaScript Injection Vulnerability in the OmniAccess Stellar Web Management Interface | |
Weaknesses | CWE-77 |
Wed, 16 Jul 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS). | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CSA
Published: 2025-07-16T06:15:05.328Z
Updated: 2025-07-16T14:41:09.909Z
Reserved: 2025-06-19T06:04:41.986Z
Link: CVE-2025-52687

No data.

Status : Awaiting Analysis
Published: 2025-07-16T07:15:21.683
Modified: 2025-07-16T14:58:59.837
Link: CVE-2025-52687

No data.