Impact
The SetParameter command on X‑Rite MA‑T6 fails to sanitize and validate incoming data, a classic operating‑system command injection flaw categorized as CWE‑78. An unauthenticated attacker can craft a request that causes the device to execute arbitrary code with the privileges of the firmware process. Successful exploitation results in complete control over the device, allowing the attacker to alter configurations, exfiltrate data, or pivot to other network assets.
Affected Systems
The vulnerability applies exclusively to X‑Rite MA‑T6 handheld colorimeters. No specific firmware versions are listed, so all releases are potentially affected until a patch addressing the input validation defect is deployed.
Risk and Exploitability
The CVSS score of 9.8 denotes critical severity, while the EPSS score of < 1% indicates a low but non‑zero exploitation probability. The flaw is not cataloged in the CISA KEV list. Attackers would typically access the exposed SetParameter interface over the network, transmit a forged command, and trigger remote code execution without the need for credentials.
OpenCVE Enrichment