Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25499 | Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system. |
Sun, 24 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danfoss
Danfoss ak-sm8xxa Series |
|
| Vendors & Products |
Danfoss
Danfoss ak-sm8xxa Series |
Fri, 22 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Aug 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system. | |
| Title | Post-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA Series | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Danfoss
Published:
Updated: 2025-08-22T11:25:28.640Z
Reserved: 2025-04-16T10:32:42.818Z
Link: CVE-2025-41451
Updated: 2025-08-22T10:59:58.245Z
Status : Deferred
Published: 2025-08-22T03:15:29.980
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41451
No data.
OpenCVE Enrichment
Updated: 2025-08-23T17:27:27Z
EUVD