CVE-2025-4692
Last modified
CVE-2025-4692 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud Update Platform.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud Update Platform.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-4692?
How severe is CVE-2025-4692?
How do I fix CVE-2025-4692?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46914Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46915Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46916Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46917Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46918Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46919Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46920Adobe Experience Manager versions 6.5.22 and earlier are aff…4.6
- CVE-2025-46922Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46923Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46924Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46926Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-46927Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
Are you affected by CVE-2025-4692?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
