Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27984 | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel. |
Solution
The vulnerability has been resolved by the Intellian Technologies team in the Q2 2025 release.
Workaround
No workaround given by the vendor.
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel. | |
| Title | Injection vulnerability in Iridium Certus 700 | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-27T14:39:15.642Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41378
Updated: 2025-05-27T14:39:12.860Z
Status : Awaiting Analysis
Published: 2025-05-23T13:15:33.307
Modified: 2025-05-23T15:54:42.643
Link: CVE-2025-41378
No data.
OpenCVE Enrichment
No data.
EUVD