CVE-2025-10159 | Sophos AP6 Wireless Access Points prior 1.7.2563 (MR7) unverified password change
A vulnerability described as very critical has been identified in Sophos AP6 Wireless Access Points. Affected by this issue is some unknown functionality. The manipulation results in unverified password change.
This vulnerability is reported as CVE-2025-10159. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.