CVE-2025-52690

8.1

Alcatel-Lucent · OmniAccess Stellar AP1100, AP1200, AP1300, AP1400, AP1500

A command injection vulnerability in Alcatel-Lucent OmniAccess Stellar access points allows unauthenticated attackers to execute arbitrary commands as root.

Executive summary

A critical command injection vulnerability in Alcatel-Lucent OmniAccess Stellar access points permits unauthenticated remote code execution with root privileges, posing a severe risk to network infrastructure.

Vulnerability

This is a command injection vulnerability (CWE-77) occurring due to improper neutralization of special elements used in system commands. The vulnerability is exploitable by an unauthenticated attacker over the network, allowing for full system compromise.

Business impact

The ability for an unauthenticated attacker to execute commands with root privileges grants them total control over the affected access points. This risk is classified as high with a CVSS score of 8.1, indicating that successful exploitation could lead to full network compromise, eavesdropping on wireless traffic, and the potential for lateral movement into the internal corporate network.

Remediation

Immediate Action: Contact your authorized Alcatel-Lucent Enterprise Business Partner immediately to coordinate an update to the latest available AWOS firmware version.

Proactive Monitoring: Review system and authentication logs for anomalous command execution patterns or unauthorized configuration changes on access point management interfaces.

Compensating Controls: Implement strict network segmentation to isolate management interfaces of access points from untrusted network segments and deploy WAF or IPS rules to identify and block malicious command injection strings.

Exploitation status

Public Exploit Available: No (there is no confirmed public exploit in the available data).

Analyst recommendation

Given the potential for complete device takeover and the availability of proof-of-concept research, this vulnerability presents an urgent security risk. Organizations utilizing affected Alcatel-Lucent OmniAccess Stellar hardware must prioritize coordination with their support partners to secure the necessary firmware updates and ensure all devices are patched to a version beyond 5.0.2 GA.

Sources

Originally found and disclosed by Lam Jun Rong, per the CVE Program record.