Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been resolved by the Intellian Technologies team in the Q2 2025 release.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27984 | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel. |
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel. | |
| Title | Injection vulnerability in Iridium Certus 700 | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-27T14:39:15.642Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41378
Updated: 2025-05-27T14:39:12.860Z
Status : Deferred
Published: 2025-05-23T13:15:33.307
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41378
No data.
OpenCVE Enrichment
No data.
EUVD