ThingsBoard, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with ThingsBoard.
Products
Clear product- ThingsBoard1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-34282MEDIUM | ThingsBoard < v4.2.1 SVG Image SSRFThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes the SVG file in a way that parses external references, it may initiate unintended outbound requests. This can be used to access internal services or resources. CWE-918Oct 17, 2025 | CVSS6.9v4.0 | EPSS1.7% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |