CVE-2025-47900
HIGHMicrochip Time Provider 4100 < 2.5 - OS Command Injection
Title source: llmDescription
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-remote-command-execution
Technical Description technical-description
https://www.gruppotim.it/en/footer/TIM-red-team.html
Scores
CVSS v3
8.8
EPSS
0.0157
EPSS Percentile
72.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
Microchip/Time Provider 4100
< 2.5
microchip/timeprovider_4100_firmware
< 2.5
Published
Oct 20, 2025
Tracked Since
Feb 18, 2026