CVE-2025-41378
MEDIUMIntellian Technologies Iridium Certus 700 >=1.0.1 <1.0.1 - OS Command Injection via SSID Field
Title source: llmDescription
The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.
References (1)
Core 1
Core References
Scores
CVSS v4
6.9
EPSS
0.0021
EPSS Percentile
11.0%
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (1)
Intellian Technologies/Iridium Certus 700
1.0.1
Published
May 23, 2025
Tracked Since
Feb 18, 2026