CVE-2025-8286
Güralp Systems FMUS Series and MIN Series Devices
Record summary
CVE-2025-8286 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.
Description
The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Güralp FMUS SeriesBrowse Güralp Systems / Güralp FMUS SeriesDefault status: unaffected | CVE List | All versions | affected |
MIN Series DevicesBrowse Güralp Systems / MIN Series DevicesDefault status: unaffected | CVE List | All versions | affected |
Nuclei templates
1ProjectDiscoveryCRITICALGüralp Systems FMUS Series - Unauthenticated AccessCVSS 9.8
Güralp Systems FMUS Series Seismic Monitoring Devices expose an unauthenticated Telnet-based command line interface that allows attackers to modify hardware configurations, manipulate data, or factory reset the device.
Impact
Successful exploitation of this vulnerability could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.
Remediation
Update to the latest firmware version or apply vendor recommended patches to secure Telnet access.
Source: ProjectDiscovery