CVE-2025-4008

HIGH(8.8)KEVWahrscheinlich ausgenutzt

Smartbedded Meteobridge Command Injection Vulnerability

Beschreibung

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

KEV-Informationen

Hersteller
Smartbedded
Produkt
Meteobridge
Hinzugefügt am
2. Oktober 2025
Fälligkeitsdatum
23. Oktober 2025
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
ADJACENT_NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
2.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
smartbeddedmeteobridge vm< 6.2
smartbeddedmeteobridge firmware< 6.2

Referenzen

CVSS-Score

8.8
HIGH(8.8)

EPSS-Score

EPSS-Score95.10%
EPSS-Perzentil99.9%

Daten

Veröffentlicht21. Mai 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.