Metrics
Affected Vendors & Products
Fri, 03 Oct 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Smartbedded
Smartbedded meteobridge Firmware Smartbedded meteobridge Vm |
|
CPEs | cpe:2.3:a:smartbedded:meteobridge_vm:*:*:*:*:*:*:*:* cpe:2.3:o:smartbedded:meteobridge_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Smartbedded
Smartbedded meteobridge Firmware Smartbedded meteobridge Vm |
|
Metrics |
cvssV3_1
|
Thu, 02 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 23 May 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 21 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 21 May 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. | |
Title | Arbitrary Command Injection in Smartbedded MeteoBridge | |
Weaknesses | CWE-306 CWE-77 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ONEKEY
Published: 2025-05-21T15:31:23.118Z
Updated: 2025-10-02T16:20:25.081Z
Reserved: 2025-04-27T08:21:52.184Z
Link: CVE-2025-4008

Updated: 2025-05-21T19:28:48.876Z

Status : Analyzed
Published: 2025-05-21T16:15:33.987
Modified: 2025-10-03T14:29:04.467
Link: CVE-2025-4008

No data.