CVE-2025-60534

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:blueaccesstech:cobalt_x1:02.000.195:*:*:*:*:*:*:*

History

29 Jan 2026, 01:24

Type Values Removed Values Added
First Time Blueaccesstech
Blueaccesstech cobalt X1
CPE cpe:2.3:a:blueaccesstech:cobalt_x1:02.000.195:*:*:*:*:*:*:*
References () http://blue.com - () http://blue.com - Broken Link
References () https://github.com/PilotPatrickk/Published-CVEs/blob/main/CVE-2025-60534.md - () https://github.com/PilotPatrickk/Published-CVEs/blob/main/CVE-2025-60534.md - Third Party Advisory

06 Jan 2026, 19:16

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 17:15

Updated : 2026-01-29 01:24


NVD link : CVE-2025-60534

Mitre link : CVE-2025-60534

CVE.ORG link : CVE-2025-60534


JSON object : View

Products Affected

blueaccesstech

  • cobalt_x1
CWE
CWE-287

Improper Authentication