CVE Explorer
CVE-2025-8679
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obtain network access. Client360 logs may display the client MAC as the username despite no MAC-authentication being enabled.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","product":"ExtremeGuest Essentials","vendor":"Extreme Networks","versions":[{"status":"affected","version":"25.4.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bca7cc0889df61c2ae1717d99a098292a780302ee4b3406226cc5a1bd8d7bd9d · sha256:1a0c4033b4d2950d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.6,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"H…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bca7cc0889df61c2ae1717d99a098292a780302ee4b3406226cc5a1bd8d7bd9d · sha256:1a0c4033b4d2950d… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-307","description":"CWE-307 Improper Restriction of Excessive Authentication Attempts","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bca7cc0889df61c2ae1717d99a098292a780302ee4b3406226cc5a1bd8d7bd9d · sha256:1a0c4033b4d2950d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://extreme-networks.my.site.com/ExtrArticleDetail?an=000130289"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bca7cc0889df61c2ae1717d99a098292a780302ee4b3406226cc5a1bd8d7bd9d · sha256:1a0c4033b4d2950d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.