EXECUTIVE SUMMARY:
A critical authentication bypass vulnerability has been discovered in Sophos AP6 Series Wireless Access Points, tracked as CVE-2025-10159. This flaw allows unauthenticated remote attackers to gain access to the management interface, potentially leading to full device takeover and network compromise.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical authentication bypass vulnerability has been discovered in Sophos AP6 Series Wireless Access Points, tracked as CVE-2025-10159. This flaw allows unauthenticated remote attackers to gain access to the management interface, potentially leading to full device takeover and network compromise.[emaillocker id="1283"]
This exposure is especially dangerous in environments where APs are deployed at scale, as a single compromise can cascade across multiple connected devices and users.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]