The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
History

Fri, 23 May 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Wed, 21 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 May 2025 15:45:00 +0000

Type Values Removed Values Added
Description The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
Title Arbitrary Command Injection in Smartbedded MeteoBridge
Weaknesses CWE-306
CWE-77
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ONEKEY

Published: 2025-05-21T15:31:23.118Z

Updated: 2025-05-23T08:04:48.828Z

Reserved: 2025-04-27T08:21:52.184Z

Link: CVE-2025-4008

cve-icon Vulnrichment

Updated: 2025-05-21T19:28:48.876Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-21T16:15:33.987

Modified: 2025-05-23T08:15:18.633

Link: CVE-2025-4008

cve-icon Redhat

No data.