216.73.217.22

CVE-2025-57605

· Published 22/09/2025 16:15 · Modified 23/09/2025 19:15

Labels: CVE-2025-57605 2025-09-22CVE-2025-57605CWE-862[email protected]

Essential information

Published
22/09/2025 16:15
Modified
23/09/2025 19:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
aikaan / aikaan iot platform cpe:2.3:a:aikaan:aikaan_iot_platform:*:*:*:*:*:*:*:*

References