Beveiligingsadvies

CVE-2025-27804

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-21 11:35:11
Laatst bijgewerkt 2025-11-03 19:46:30
Toegewezen door SEC-VLab
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic arbitrary OS commands can be executed with root permissions.