Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/emoncms/emoncms/issues/1941 |
|
Tue, 28 Oct 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openenergymonitor
Openenergymonitor emoncms |
|
| CPEs | cpe:2.3:a:openenergymonitor:emoncms:11.7.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Openenergymonitor
Openenergymonitor emoncms |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emoncms
Emoncms emoncms |
|
| Vendors & Products |
Emoncms
Emoncms emoncms |
Fri, 24 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
cvssV3_1
|
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset within the /admin/upload-custom-firmware endpoint. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-24T15:41:40.958Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60938
Updated: 2025-10-24T15:40:49.581Z
Status : Analyzed
Published: 2025-10-24T15:15:40.577
Modified: 2025-10-28T02:32:37.637
Link: CVE-2025-60938
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:13:02Z