← Back to browse · API

CVE-2025-4008

Severity
HIGH
CVSS
8.7
EPSS
0.95104
Risk score
58.29
CISA KEV
Yes
PoC
No
Published
2025-05-21
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-16032, GHSA-G7H8-28JJ-QXMF
Products
Smartbedded:MeteoBridge 0 ≤6.1, Smartbedded:Meteobridge
Sources
cisa.gov CVE-2025-4008
euvd EUVD-2025-16032

Description

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

References