#VU116272 Improper Authorization in ExtremeCloud IQ Essentials - CVE-2025-8679
Published: October 1, 2025
ExtremeCloud IQ Essentials
Extreme Networks
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper authorization checks. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obtain network access.