Home

Description

MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP request crafted by an authenticated user could allow the execution of arbitrary commands on the underlying operating system.

PUBLISHED Reserved 2025-08-08 | Published 2025-08-08 | Updated 2025-11-05 | Assigner TRO




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

Any version before 3.0.0
affected

Default status
unaffected

Any version before 3.0.0
affected

Credits

Lockheed Martin Red Team reporter

References

mobile-industrial-robots.com/...advisories/command-injection vendor-advisory

supportportal.mobile-industrial-robots.com/...ecurity-guide/

cve.org (CVE-2025-8748)

nvd.nist.gov (CVE-2025-8748)

Download JSON