CVE-2025-4692: Abup IoT Cloud Platform
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud Update Platform.
Affected products
- Abup Abup IoT Cloud Platform: any version
Published 2025-05-23. Last modified 2026-06-17.