Home

Description

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

PUBLISHED Reserved 2025-09-19 | Published 2026-03-04 | Updated 2026-03-04 | Assigner 2N




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Problem types

CWE-1286 – Improper Validation of Syntactic Correctness

Product status

Default status
unaffected

Any version before 3.5
affected

References

www.2n.com/en-GB/download/cve_2025_59785_acom_3_5_v1pdf vendor-advisory

cve.org (CVE-2025-59785)

nvd.nist.gov (CVE-2025-59785)

Download JSON