Vulnerability Description
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-57605?
CVE-2025-57605 is a vulnerability with a CVSS score of 8.8 (HIGH). Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departmen...
How severe is CVE-2025-57605?
CVE-2025-57605 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57605?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.