CVE-2025-27493: Input Validation
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize user input for specific commands on the telnet command line interface. This could allow an authenticated local administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiPass integrated AC5102 (ACC-G2)to a version that resolves this vulnerability.Fixed in V6.4.9 - Upgrade
Upgrade
SiPass integrated ACC-APto a version that resolves this vulnerability.Fixed in V6.4.9
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27493?
CVE-2025-27493 is rated as critical due to improper input sanitization that could allow unauthorized command execution.
How do I fix CVE-2025-27493?
To fix CVE-2025-27493, upgrade SiPass integrated AC5102 (ACC-G2) and SiPass integrated ACC-AP to version 6.4.9 or later.
What devices are affected by CVE-2025-27493?
CVE-2025-27493 affects SiPass integrated AC5102 (ACC-G2) and SiPass integrated ACC-AP versions prior to 6.4.9.
What exploitation methods exist for CVE-2025-27493?
Exploitation of CVE-2025-27493 can occur through authenticated access to the telnet command line interface.
Is CVE-2025-27493 remote or local?
CVE-2025-27493 requires local authentication to exploit the vulnerability via the telnet interface.