CVE Feed

    Dashboard / CVE / CVE-2025-8679

    CVE-2025-8679

    In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obtain network access. Client360 logs may display the client MAC as the username despite no MAC-authentication being enabled.

    Published:Oct 1, 2025
    Last Modified:Jan 15, 2026
    EPS:Oct 1, 2025
    EPSS Score:0.00035
    CVSS Score:9.8

    Affected Products

    Vendor
    Extreme Networks
    Product
    Extremeguest Essentials
    Vendor
    Extremenetworks
    Product
    Extremeguest Essentials

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High