PT-2025-40280 · Extreme Networks · Extremeguest Essentials

Published

2025-10-01

·

Updated

2025-10-02

·

CVE-2025-8679

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ExtremeGuest Essentials versions prior to 25.5.0
Description The captive-portal feature may allow unauthorized access through manual brute-force attempts. Specific ExtremeGuest Essentials captive-portal SSID configurations could allow an unauthenticated device to be incorrectly marked as authenticated, granting network access. Client360 logs might incorrectly display the client MAC address as the username, even when MAC authentication is not enabled.
Recommendations Update to version 25.5.0 or later.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2025-8679

Affected Products

Extremeguest Essentials