CVE-2025-10159: Critical severity Sophos AP6 Series Wireless Access Points vulnerability
Published Sep 9, 2025
·Updated
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
Affected Software
1 affected component
Sophos AP6 Series Wireless Access Points<1.7.2563
Event History
Sep 9, 2025
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-10159?
CVE-2025-10159 has a high severity rating as it enables remote attackers to gain administrative privileges.
2
How do I fix CVE-2025-10159?
To fix CVE-2025-10159, update the firmware of Sophos AP6 Series Wireless Access Points to version 1.7.2563 or later.
3
Who is affected by CVE-2025-10159?
CVE-2025-10159 affects Sophos AP6 Series Wireless Access Points running firmware versions older than 1.7.2563.
4
What type of attack does CVE-2025-10159 allow?
CVE-2025-10159 allows an authentication bypass attack, enabling unauthorized administrative access.
5
When was CVE-2025-10159 disclosed?
CVE-2025-10159 was disclosed on September 9, 2025.