{"cve":{"cve_id":"CVE-2025-52687","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00229,"epss_percentile":0.13441,"epss_as_of":"2026-06-23","description":"Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).","published_at":"2025-07-16T06:15:05.328000Z","last_modified_at":null,"cvss_v3_score":2.4,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","cvss_v3_severity":"LOW","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-77"],"nvd_references":["https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/","https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:27:26.287160Z"},"effective_severity":"LOW","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"H","value_label":"High"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"N","value_label":"None"},{"metric":"I","name":"Integrity","value":"L","value_label":"Low"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"alcatel-lucent","vendor_name":"Alcatel-Lucent","product_slug":"omniaccess-stellar","product_name":"OmniAccess Stellar","version_start":"AP1100 AWOS versions 5.0.2 GA and earlier","version_start_inclusive":true,"version_end":"AP1100 AWOS versions 5.0.2 GA and earlier","version_end_inclusive":true,"cpe23_uri":"cve5:alcatel-lucent:omniaccess-stellar:AP1100 AWOS versions 5.0.2 GA and earlier:AP1100 AWOS versions 5.0.2 GA and earlier"},{"vendor_slug":"alcatel-lucent","vendor_name":"Alcatel-Lucent","product_slug":"omniaccess-stellar","product_name":"OmniAccess Stellar","version_start":"AP1200 AWOS versions 5.0.2 GA and earlier","version_start_inclusive":true,"version_end":"AP1200 AWOS versions 5.0.2 GA and earlier","version_end_inclusive":true,"cpe23_uri":"cve5:alcatel-lucent:omniaccess-stellar:AP1200 AWOS versions 5.0.2 GA and earlier:AP1200 AWOS versions 5.0.2 GA and earlier"},{"vendor_slug":"alcatel-lucent","vendor_name":"Alcatel-Lucent","product_slug":"omniaccess-stellar","product_name":"OmniAccess Stellar","version_start":"AP1300 AWOS versions 5.0.2 GA and earlier","version_start_inclusive":true,"version_end":"AP1300 AWOS versions 5.0.2 GA and earlier","version_end_inclusive":true,"cpe23_uri":"cve5:alcatel-lucent:omniaccess-stellar:AP1300 AWOS versions 5.0.2 GA and earlier:AP1300 AWOS versions 5.0.2 GA and earlier"},{"vendor_slug":"alcatel-lucent","vendor_name":"Alcatel-Lucent","product_slug":"omniaccess-stellar","product_name":"OmniAccess Stellar","version_start":"AP1400 AWOS versions 5.0.2 GA and earlier","version_start_inclusive":true,"version_end":"AP1400 AWOS versions 5.0.2 GA and earlier","version_end_inclusive":true,"cpe23_uri":"cve5:alcatel-lucent:omniaccess-stellar:AP1400 AWOS versions 5.0.2 GA and earlier:AP1400 AWOS versions 5.0.2 GA and earlier"},{"vendor_slug":"alcatel-lucent","vendor_name":"Alcatel-Lucent","product_slug":"omniaccess-stellar","product_name":"OmniAccess Stellar","version_start":"AP1500 AWOS versions 5.0.2 GA and earlier","version_start_inclusive":true,"version_end":"AP1500 AWOS versions 5.0.2 GA and earlier","version_end_inclusive":true,"cpe23_uri":"cve5:alcatel-lucent:omniaccess-stellar:AP1500 AWOS versions 5.0.2 GA and earlier:AP1500 AWOS versions 5.0.2 GA and earlier"}],"exploit_refs":[],"news":[],"references":[{"url":"https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-072/","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://www.al-enterprise.com/-/media/assets/internet/documents/sa-n0150-omniaccess-stellar-multiple-vulnerabilities.pdf","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2025-07-16T06:15:05.328000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:47:31.968567Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:47:31.968567Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:47:31.968567Z","label":"CVSS score revised","source":"cvelistv5"}]}