Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}


Wed, 16 Jul 2025 06:45:00 +0000

Type Values Removed Values Added
Title JavaScript Injection Vulnerability in the OmniAccess Stellar Web Management Interface
Weaknesses CWE-77

Wed, 16 Jul 2025 06:30:00 +0000

Type Values Removed Values Added
Description Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).
References
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published: 2025-07-16T06:15:05.328Z

Updated: 2025-07-16T14:41:09.909Z

Reserved: 2025-06-19T06:04:41.986Z

Link: CVE-2025-52687

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-16T07:15:21.683

Modified: 2025-07-16T14:58:59.837

Link: CVE-2025-52687

cve-icon Redhat

No data.