Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Oct 23, 2025

High
CISA KEV

CVE-2025-4008

SmartbeddedMeteobridge

Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices.

Required Action

https://forum.meteohub.de/viewtopic.php?t=18687 ; https://nvd.nist.gov/vuln/detail/CVE-2025-4008

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Published
Oct 2, 2025
KEV Added
Oct 2, 2025
Due Date
Oct 23, 2025
Related Articles
0

Vendor

Smartbedded

Meteobridge