← back
CVE-2025-52626mediumCWE-78

HCL AION is susceptible to Potential Command Injection vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.5epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
In short

HCL AION 2.0 has a flaw that allows attackers to inject and execute unauthorized commands on the system. This could let them perform harmful actions beyond what they should be allowed to do.

Technical detail

CWE-78 command injection vulnerability in HCL AION 2.0 permits an attacker to inject malicious commands through application input, leading to unintended command execution with the privileges of the running process. Exploitation requires application interaction but can result in unauthorized system-level actions and potential compromise of the underlying infrastructure.

Summary generated and translated by AI from the official description.
A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
HCL · AION