Metrics
Affected Vendors & Products
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 23 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 21 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. | |
| Title | Arbitrary Command Injection in Smartbedded MeteoBridge | |
| Weaknesses | CWE-306 CWE-77 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ONEKEY
Published: 2025-05-21T15:31:23.118Z
Updated: 2025-05-23T08:04:48.828Z
Reserved: 2025-04-27T08:21:52.184Z
Link: CVE-2025-4008
Updated: 2025-05-21T19:28:48.876Z
Status : Awaiting Analysis
Published: 2025-05-21T16:15:33.987
Modified: 2025-05-23T08:15:18.633
Link: CVE-2025-4008
No data.