{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-52690",
        "assignerOrgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "state": "PUBLISHED",
        "assignerShortName": "CSA",
        "dateReserved": "2025-06-19T06:04:41.987Z",
        "datePublished": "2025-07-16T06:34:02.704Z",
        "dateUpdated": "2025-07-16T14:40:53.098Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unknown",
                    "product": "OmniAccess Stellar Products",
                    "vendor": "Alcatel-Lucent",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "AP1100 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1200 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1300 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1400 AWOS versions 5.0.2 GA and earlier"
                        },
                        {
                            "status": "affected",
                            "version": "AP1500 AWOS versions 5.0.2 GA and earlier"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Lam Jun Rong"
                }
            ],
            "datePublic": "2025-07-16T06:31:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point."
                        }
                    ],
                    "value": "Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "HIGH",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "HIGH",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-77",
                            "description": "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
                "shortName": "CSA",
                "dateUpdated": "2025-07-16T06:34:02.704Z"
            },
            "references": [
                {
                    "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/"
                },
                {
                    "url": "https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf"
                },
                {
                    "url": "https://jro.sg/CVEs/CVE-2025-52690/"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Users and administrators of affected products are advised to contact their Business Partner immediately to update to the latest version."
                        }
                    ],
                    "value": "Users and administrators of affected products are advised to contact their Business Partner immediately to update to the latest version."
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Command Injection Vulnerability in the OmniAccess Stellar over UDP Service",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "references": [
                    {
                        "url": "https://jro.sg/CVEs/CVE-2025-52690/",
                        "tags": [
                            "exploit"
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-07-16T14:35:23.553527Z",
                                "id": "CVE-2025-52690",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-07-16T14:40:53.098Z"
                }
            }
        ]
    }
}