Indoor Connect 8855 contains a command injection vulnerability which if
exploited can lead to loss of integrity and confidentiality, as well as
unauthorized disclosure and modification of user and configuration data. It
may also be possible to execute commands with escalated privileges, impact
service availability, as well as modify system files and configuration
data.
Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 26 Sep 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ericsson
Ericsson indoor Connect 8855 |
|
Vendors & Products |
Ericsson
Ericsson indoor Connect 8855 |
Thu, 25 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 25 Sep 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can lead to loss of integrity and confidentiality, as well as unauthorized disclosure and modification of user and configuration data. It may also be possible to execute commands with escalated privileges, impact service availability, as well as modify system files and configuration data. | |
Title | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerability | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ERIC
Published:
Updated: 2025-09-25T15:27:05.382Z
Reserved: 2025-02-21T08:58:20.367Z
Link: CVE-2025-27262

Updated: 2025-09-25T15:27:02.551Z

Status : Awaiting Analysis
Published: 2025-09-25T15:16:10.737
Modified: 2025-09-26T14:32:53.583
Link: CVE-2025-27262

No data.

Updated: 2025-09-26T11:35:46Z