CVE-2025-4692

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/05/2025
Last modified:
23/05/2025

Description

Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the <br /> <br /> ABUP Cloud Update Platform.

References to Advisories, Solutions, and Tools