CVE-2025-52352

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functional, allowing unauthenticated users to register accounts via APIs even when the feature is disabled. This leads to authentication bypass and unauthorized access to admin portals, violating intended access controls.
Configurations

No configuration.

History

No history.

Information

Published : 2025-08-21 18:15

Updated : 2025-08-22 18:08


NVD link : CVE-2025-52352

Mitre link : CVE-2025-52352

CVE.ORG link : CVE-2025-52352


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization