PT-2025-38732 · Unknown · Aikaan Iot Platform

CVE-2025-57605

·

Published

2025-09-22

·

Updated

2025-09-22

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AiKaan IoT Platform (affected versions not specified)
Description A missing server-side authorization check in the department admin assignment APIs within the AiKaan IoT Platform permits authenticated users to gain elevated privileges. Specifically, users can assign themselves as administrators of departments they do not have authorization to manage, leading to unauthorized privilege escalation. The affected API endpoints handle department admin assignments. The vulnerable functionality allows users to manipulate their department admin status.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57605

Affected Products

Aikaan Iot Platform