Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.
References
| Link | Resource |
|---|---|
| http://blue.com | Broken Link |
| https://github.com/PilotPatrickk/Published-CVEs/blob/main/CVE-2025-60534.md | Third Party Advisory |
Configurations
History
29 Jan 2026, 01:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Blueaccesstech
Blueaccesstech cobalt X1 |
|
| CPE | cpe:2.3:a:blueaccesstech:cobalt_x1:02.000.195:*:*:*:*:*:*:* | |
| References | () http://blue.com - Broken Link | |
| References | () https://github.com/PilotPatrickk/Published-CVEs/blob/main/CVE-2025-60534.md - Third Party Advisory |
06 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
06 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-06 17:15
Updated : 2026-01-29 01:24
NVD link : CVE-2025-60534
Mitre link : CVE-2025-60534
CVE.ORG link : CVE-2025-60534
JSON object : View
Products Affected
blueaccesstech
- cobalt_x1
CWE
CWE-287
Improper Authentication
