---
id: CVE-2025-52625
title: "A vulnerability\_\n\nCacheable SSL Page Found vulnerability has been identified\n\n in HCL AION.\_\n\nCached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser\n\nThis issue af…"
summary: "A vulnerability\_\n\nCacheable SSL Page Found vulnerability has been identified\n\n in HCL AION.\_\n\nCached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser\n\nThis issue af…"
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-525
vendor: hcltech
product: aion
affected:
  - aion = 2.0.0
published: '2025-10-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52625'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124444
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00237
epssPercentile: 0.13507
ingestedAt: '2026-10-08T13:42:55.081Z'
---

## Overview

A vulnerability 

Cacheable SSL Page Found vulnerability has been identified

 in HCL AION. 

Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser

This issue affects AION: 2.0.

## Affected

- `aion = 2.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
