CVE Vulnerabilities

CVE-2025-10159

Unverified Password Change

Published: Sep 09, 2025 | Modified: Sep 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Potential Mitigations

References