CVE-2025-6685 HIGH

CVE-2025-6685: ATEN eco DC Missing Authorization Privilege Escalation Vulnerability

Vendor Aten
Product eco DC
Weakness CWE-862 · Missing authorization
Published September 2, 2025
Last update September 2, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of ATEN eco DC. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based interface. The issue results from the lack of validating the assigned user role when handling requests. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26647.

Key dates

02Disclosure timeline

September 2, 2025 CVE published
September 2, 2025 Record updated

Related vulnerabilities

04Related CVE