PT-2025-22569 · Unknown · Abup Cloud Update Platform

Daniel Christensen

·

Published

2025-05-22

·

Updated

2025-05-23

·

CVE-2025-4692

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions ABUP Cloud Update Platform (affected versions not specified)
Description The issue allows actors to perform privilege escalation by submitting a maliciously crafted JavaScript object notation (JSON) web token (JWT) to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the platform.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-4692

Affected Products

Abup Cloud Update Platform