Access prior to version 14.10. Attackers with access to the console can
redirect victims to an arbitrary URL. The attack complexity is low, attack
requirements are present, no privileges are required, and users must actively
participate in the attack. Impact to confidentiality is low and there is no
impact to integrity or availability. There are high severity impacts to
confidentiality, integrity, availability in subsequent systems.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32208 | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact to confidentiality is low and there is no impact to integrity or availability. There are high severity impacts to confidentiality, integrity, availability in subsequent systems. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 16 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 07 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
ssvc
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Absolute
Absolute secure Access |
|
| Vendors & Products |
Absolute
Absolute secure Access |
Thu, 02 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact to confidentiality is low and there is no impact to integrity or availability. There are high severity impacts to confidentiality, integrity, availability in subsequent systems. | |
| Title | Open Redirect in Secure Access prior to 14.10 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Absolute
Published:
Updated: 2025-10-07T19:26:28.230Z
Reserved: 2025-07-16T17:10:03.453Z
Link: CVE-2025-54088
Updated: 2025-10-07T19:26:24.927Z
Status : Analyzed
Published: 2025-10-02T21:16:00.740
Modified: 2025-10-16T18:22:01.223
Link: CVE-2025-54088
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:33Z
EUVD