CVE-2025-60534

B

lue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:blueaccesstech:cobalt_x1:02.000.195:*:*:*:*:*:*:*

History

29 Jan 2026, 01:24

Type Values Removed Values Added
References () http://blue.com - () http://blue.com - Broken Link
References () https://github.com/PilotPatrickk/Published-CVEs/blob/main/CVE-2025-60534.md - () https://github.com/PilotPatrickk/Published-CVEs/blob/main/CVE-2025-60534.md - Third Party Advisory
First Time Blueaccesstech cobalt X1
Blueaccesstech
CPE cpe:2.3:a:blueaccesstech:cobalt_x1:02.000.195:*:*:*:*:*:*:*

06 Jan 2026, 19:16

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 17:15

Updated : 2026-01-29 01:24


NVD link : CVE-2025-60534

Mitre link : CVE-2025-60534

CVE.ORG link : CVE-2025-60534


JSON object : View

Products Affected
CWE
CWE-287

Improper Authentication