← Back to browse · API

CVE-2025-2605

Severity
CRITICAL
CVSS
9.9
EPSS
0.13412
Risk score
44.29
CISA KEV
No
PoC
No
Published
2025-05-02
Modified
2025-05-17
First seen
2026-08-07
Aliases
EUVD-2025-13247, GHSA-4P7F-6RW5-M5V7
Products
Honeywell:MB-Secure V11.04 <V12.53
Sources
euvd EUVD-2025-13247

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.

References