Improper authentication in AP6 Series Wireless Access Points - CVE-2025-10159

 

Improper authentication in AP6 Series Wireless Access Points - CVE-2025-10159

Published: September 9, 2025


Vulnerability identifier: #VU115077
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-10159
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the authentication process. A remote attacker with access to the access point’s management IP address can bypass authentication process and gain unauthorized access to the device.


Affected software

AP6 Series Wireless Access Points

How to mitigate CVE-2025-10159

Install updates from vendor's website.

AP6 Series Wireless Access Points - update to 1.7.2563

External References

Related Security Bulletins