CVE-2025-60938

HIGH

Emoncms 11.7.3 - Authenticated Remote Code Execution via Firmware Upload Feature

Title source: llm
STIX 2.1

Description

Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset within the /admin/upload-custom-firmware endpoint.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/emoncms/emoncms/issues/1941

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 41.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
openenergymonitor/emoncms 11.7.3
Published Oct 24, 2025
Tracked Since Feb 18, 2026