CVE-2025-4008
HIGH(8.8)KEVWahrscheinlich ausgenutzt
Smartbedded Meteobridge Command Injection Vulnerability
Beschreibung
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenCWEs
Betroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| smartbedded | meteobridge vm | < 6.2 |
| smartbedded | meteobridge firmware | < 6.2 |
Referenzen
- https://forum.meteohub.de/viewtopic.php?t=18687(Vendor Advisory)
- https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008(Exploit, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4008(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.