PT-2025-23273 · Unknown · Airpointer Web Platform

Published

2025-05-30

·

Updated

2025-06-04

·

CVE-2025-4636

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airpointer web platform (affected versions not specified)
Description The issue arises from excessive privileges granted to the web user running the Airpointer web platform. This allows a malicious actor who gains control of this user to escalate privileges to the root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-4636

Affected Products

Airpointer Web Platform