CVE-2025-4692: Abup IoT Cloud Platform

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud Update Platform.

Affected products

  • Abup Abup IoT Cloud Platform: any version

Published 2025-05-23. Last modified 2026-06-17.