Record summary

CVE-2025-8286 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.

Description

The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListAll versionsaffected

Default status: unaffected

CVE ListAll versionsaffected

Nuclei templates

1
ProjectDiscoveryCRITICALGüralp Systems FMUS Series - Unauthenticated AccessCVSS 9.8

Güralp Systems FMUS Series Seismic Monitoring Devices expose an unauthenticated Telnet-based command line interface that allows attackers to modify hardware configurations, manipulate data, or factory reset the device.

Impact

Successful exploitation of this vulnerability could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.

Remediation

Update to the latest firmware version or apply vendor recommended patches to secure Telnet access.

WeaknessesCWE-306
Authorsdarses
Template tagscvecve2025tcpnetworktelnetguralpicsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: "Welcome to " "list of available commands" port:4244
FOFA: "Welcome to " && "list of available commands" && port="4244"

Source: ProjectDiscovery

References

2