CVE-2025-4008
Arbitrary Command Injection in Smartbedded MeteoBridge
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 27, 2025
- Published Date
- May 21, 2025
- Last Updated
- February 26, 2026
- Vendor
- Smartbedded
- Product
- MeteoBridge
- Description
- The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
- Tags
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
- Exploited in the Wild
- Yes (2026-06-01 10:41:37 UTC) Source
cisa
nuclei_scanner
CVSS Scores
CVSS v4.0
8.7 - HIGH
Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2026-06-01 10:41:37 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4008.yaml | 2025-06-02 14:11:04 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei
-
Added to KEVIntel