CVE-2025-57605
BaseFortify
Publication date: 2025-09-22
Last updated on: 2025-09-23
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aikaan | iot_platform | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a lack of server-side authorization in the department admin assignment APIs of the AiKaan IoT Platform. It allows authenticated users to assign themselves as admins of other departments, which they should not be able to do. Essentially, users can elevate their privileges without proper permission checks.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized privilege escalation, meaning users can gain admin rights in departments where they should not have them. This can result in unauthorized access to sensitive data, control over department resources, and potential misuse or manipulation of the system.