SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-4008

Smartbedded Meteobridge Command Injection Vulnerability

KEVHIGH 8.7EPSS 93.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 23 October 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

CVSS 4.0
8.7 HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
93.67% probability · 100th percentile
CISA KEV
Listed 2 October 2025 · due 23 October 2025
Weakness
CWE-77, CWE-306
Affected
smartbedded/meteobridge vm · smartbedded/meteobridge firmware
Source
research@onekey.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://forum.meteohub.de/viewtopic.php?t=18687 ; https://nvd.nist.gov/vuln/detail/CVE-2025-4008

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.