216.73.216.6

CVE-2025-57602

· Published 22/09/2025 16:15 · Modified 23/09/2025 19:15

Labels: CVE-2025-57602 2025-09-22CVE-2025-57602CWE-798[email protected]

Essential information

Published
22/09/2025 16:15
Modified
23/09/2025 19:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot into other connected IoT devices. This can lead to remote code execution, information disclosure, and privilege escalation across customer environments.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
aikaan / aikaan iot management platform cpe:2.3:a:aikaan:aikaan_iot_management_platform:*:*:*:*:*:*:*:*

References