CVE-2025-27494: Input Validation
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiPass integrated AC5102 (ACC-G2)to a version that resolves this vulnerability.Fixed in V6.4.9 - Upgrade
Upgrade
SiPass integrated ACC-APto a version that resolves this vulnerability.Fixed in V6.4.9
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27494?
CVE-2025-27494 is classified as a high severity vulnerability due to potential remote code execution risks.
How do I fix CVE-2025-27494?
To fix CVE-2025-27494, upgrade your SiPass integrated AC5102 (ACC-G2) or ACC-AP devices to version V6.4.9 or later.
Who is affected by CVE-2025-27494?
CVE-2025-27494 affects all versions of the SiPass integrated AC5102 (ACC-G2) and ACC-AP prior to V6.4.9.
What type of vulnerability is CVE-2025-27494?
CVE-2025-27494 is an input validation vulnerability in the REST API that could lead to unauthorized access.
Can CVE-2025-27494 be exploited remotely?
Yes, CVE-2025-27494 can be exploited remotely by an authenticated administrator, potentially leading to privilege escalation.