The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.
Metrics
Affected Vendors & Products
References
History
Tue, 27 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 May 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel. | |
Title | Injection vulnerability in Iridium Certus 700 | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-05-23T12:40:14.121Z
Updated: 2025-05-27T14:39:15.642Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41378

Updated: 2025-05-27T14:39:12.860Z

Status : Awaiting Analysis
Published: 2025-05-23T13:15:33.307
Modified: 2025-05-23T15:54:42.643
Link: CVE-2025-41378

No data.