← back
CVE-2025-52688criticalCWE-77

Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface

53Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 23%
from disclosure to weapon0 days
Published on NVDJul 16
1st PoCJul 16
exploitation probability
23%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.