CVEFinder.io

CVE-2025-52606

đŸ”ļ medium
🔍 Scan for this CVE
Summary

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

CVSS Score
4.3
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2026-06-04
First Seen: 2026-06-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 5.4% of all 330,193 vulnerabilities in our database.

#312,358
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Jun 4, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-06-04
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 1

🔗 Related CVEs 5

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-62340 â„šī¸ low 3.1 0.2 HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where ... 2026-06-17
CVE-2025-52608 â„šī¸ low 3.1 0.0 HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s... 2026-06-04
CVE-2025-52609 â„šī¸ low 3.7 0.1 HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by... 2026-06-04
CVE-2025-52611 â„šī¸ low 3.1 0.0 HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ... 2026-06-04
CVE-2025-52612 âš ī¸ high 7.1 0.0 HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script... 2026-06-04
These CVEs affect the same products