CVE-2025-69274: Spectrum broken authorization scheme
Published Jan 12, 2026
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.
Affected Software
4 affected components
Broadcom DX NetOps Spectrum<24.3.10
All of the following
Broadcom DX NetOps Spectrum<24.3.11
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Jan 12, 2026
CVE Published
via MITRE·04:42 AM
Data Sourced
via MITRE·04:42 AM
DescriptionWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69274?
CVE-2025-69274 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2025-69274?
To remediate CVE-2025-69274, update to a version of Broadcom DX NetOps Spectrum later than 24.3.10.
3
What versions of Broadcom DX NetOps Spectrum are affected by CVE-2025-69274?
CVE-2025-69274 affects Broadcom DX NetOps Spectrum versions 24.3.10 and earlier.
4
What type of vulnerability is CVE-2025-69274?
CVE-2025-69274 is an authorization bypass vulnerability allowing for privilege escalation.
5
Can CVE-2025-69274 be exploited remotely?
Yes, CVE-2025-69274 could potentially be exploited remotely if the affected software is improperly configured.