CVE-2025-41378

MEDIUM

Intellian Technologies Iridium Certus 700 >=1.0.1 <1.0.1 - OS Command Injection via SSID Field

Title source: llm
STIX 2.1

Description

The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.

Scores

CVSS v4 6.9
EPSS 0.0021
EPSS Percentile 11.0%
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
Intellian Technologies/Iridium Certus 700 1.0.1
Published May 23, 2025
Tracked Since Feb 18, 2026