CVE-2025-57605
Last modified
CVE-2025-57605 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-57605?
How severe is CVE-2025-57605?
How do I fix CVE-2025-57605?
Are you affected by CVE-2025-57605?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
