CVE-2025-35042
CRITICALDescription
Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gaining the privileges of this account. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Is your site exposed to CVE-2025-35042?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| airship.ai | acropolis |
| airship.ai | acropolis |
| airship.ai | acropolis |
References
Frequently Asked Questions
What is CVE-2025-35042? +
How severe is CVE-2025-35042? +
What products are affected by CVE-2025-35042? +
How do I check if I'm vulnerable to CVE-2025-35042? +
Related Vulnerabilities
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters …
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. …
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can …
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created …
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might …