CVE-2025-57605
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-22

Last updated on: 2025-09-23

Assigner: MITRE

Description
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-22
Last Modified
2025-09-23
Generated
2026-05-06
AI Q&A
2025-09-22
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
aikaan iot_platform *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a lack of server-side authorization in the department admin assignment APIs of the AiKaan IoT Platform. It allows authenticated users to assign themselves as admins of other departments, which they should not be able to do. Essentially, users can elevate their privileges without proper permission checks.


How can this vulnerability impact me? :

This vulnerability can lead to unauthorized privilege escalation, meaning users can gain admin rights in departments where they should not have them. This can result in unauthorized access to sensitive data, control over department resources, and potential misuse or manipulation of the system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart