Metrics
Affected Vendors & Products
Fri, 23 May 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 21 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 21 May 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. | |
Title | Arbitrary Command Injection in Smartbedded MeteoBridge | |
Weaknesses | CWE-306 CWE-77 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ONEKEY
Published: 2025-05-21T15:31:23.118Z
Updated: 2025-05-23T08:04:48.828Z
Reserved: 2025-04-27T08:21:52.184Z
Link: CVE-2025-4008

Updated: 2025-05-21T19:28:48.876Z

Status : Awaiting Analysis
Published: 2025-05-21T16:15:33.987
Modified: 2025-05-23T08:15:18.633
Link: CVE-2025-4008

No data.