Description
Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
AP1100 AWOS versions 5.0.2 GA and earlier
AP1200 AWOS versions 5.0.2 GA and earlier
AP1300 AWOS versions 5.0.2 GA and earlier
AP1400 AWOS versions 5.0.2 GA and earlier
AP1500 AWOS versions 5.0.2 GA and earlier
Credits
Lam Jun Rong
References
jro.sg/CVEs/CVE-2025-52690/
www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/
www.al-enterprise.com/...tellar-multiple-vulnerabilities.pdf