Home

Description

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic arbitrary OS commands can be executed with root permissions.

PUBLISHED Reserved 2025-03-07 | Published 2025-05-21 | Updated 2025-11-03 | Assigner SEC-VLab

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
affected

<=2.2.0
affected

Credits

Stefan Viehböck | SEC Consult Vulnerability Lab finder

References

seclists.org/fulldisclosure/2025/May/23

r.sec-consult.com/echarge third-party-advisory

cve.org (CVE-2025-27804)

nvd.nist.gov (CVE-2025-27804)

Download JSON