Description
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.
Published: 2025-11-21
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of managed Wi‑Fi profiles via physical access
Action: Apply Update
AI Analysis

Impact

An attacker who can physically reach the device may override the network settings that are normally locked by managed Wi‑Fi profiles. The flaw is classified as a weak access control issue (CWE‑284) and is scored modestly with a CVSS of 2.4, indicating limited impact compared to higher‑score vulnerabilities.

Affected Systems

Apple iOS and iPadOS devices are affected. The vulnerability was corrected in iOS 18.5 and iPadOS 18.5, as well as iPadOS 17.7.7; older releases, including all previous iOS and iPadOS versions, remain vulnerable unless patched.

Risk and Exploitability

The EPSS score is below 1 %, the KEV list does not include this CVE, and the attack surface requires physical possession of the device. Overall this is a low‑risk issue that is unlikely to be targeted in the wild but could be exploited in a controlled environment by an insider or thief with direct device access.

Generated by OpenCVE AI on April 28, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 18.5, iPadOS 18.5, or iPadOS 17.7.7 to apply the vendor patch
  • After upgrading, review the managed Wi‑Fi profiles using the mobile device management console to confirm that no unauthorized changes have been made
  • Enforce strict physical security on devices by restricting access to authorized personnel and using device‑level locks to mitigate the risk of an attacker being able to reach the device

Generated by OpenCVE AI on April 28, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 10:45:00 +0000

Type Values Removed Values Added
Title Physical Access Allows Overriding Managed Wi‑Fi Profiles on iOS and iPadOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to override managed Wi-Fi profiles. The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.

Wed, 26 Nov 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple iphone Os

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipados
Vendors & Products Apple
Apple ios
Apple ipados

Sun, 23 Nov 2025 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:25:32.343Z

Reserved: 2025-03-27T16:13:58.317Z

Link: CVE-2025-31216

cve-icon Vulnrichment

Updated: 2025-11-23T11:26:54.762Z

cve-icon NVD

Status : Modified

Published: 2025-11-21T22:16:19.370

Modified: 2026-04-02T19:19:49.173

Link: CVE-2025-31216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:30:29Z

Weaknesses