{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-52688",
        "assignerOrgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "state": "PUBLISHED",
        "assignerShortName": "CSA",
        "dateReserved": "2025-06-19T06:04:41.986Z",
        "datePublished": "2025-07-16T06:23:53.933Z",
        "dateUpdated": "2025-07-16T14:41:04.579Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unknown",
                    "product": "OmniAccess Stellar Products",
                    "vendor": "Alcatel-Lucent",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "AP1100 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1200 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1300 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1400 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1500 AWOS versions 5.0.2 GA and earlier"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Joel Chang Zhi Kai"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Liu Yisen"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Cao Wei"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Lam Jun Rong"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "River Koh"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Yeo Jun Yi Keith"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Hyunseok Yun"
                }
            ],
            "datePublic": "2025-07-16T06:15:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point."
                        }
                    ],
                    "value": "Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "HIGH",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-77",
                            "description": "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
                "shortName": "CSA",
                "dateUpdated": "2025-07-16T06:23:53.933Z"
            },
            "references": [
                {
                    "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/"
                },
                {
                    "url": "https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf"
                },
                {
                    "url": "https://jro.sg/CVEs/CVE-2025-52688/"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Users and administrators of affected products are advised to contact their Business Partner immediately to update to the latest version.\n\n<br>"
                        }
                    ],
                    "value": "Users and administrators of affected products are advised to contact their Business Partner immediately to update to the latest version."
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "references": [
                    {
                        "url": "https://jro.sg/CVEs/CVE-2025-52688/",
                        "tags": [
                            "exploit"
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-07-16T14:37:02.110254Z",
                                "id": "CVE-2025-52688",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-07-16T14:41:04.579Z"
                }
            }
        ]
    }
}