CVE-2025-0636

8.4

Ericsson · Site Controller 6610, RAN Compute

Ericsson EMCLI is vulnerable to OS command injection, which allows an authenticated user with low privileges to execute arbitrary code on the underlying operating system.

Executive summary

A high-severity OS command injection vulnerability in Ericsson EMCLI allows authenticated attackers to achieve arbitrary code execution, posing a significant risk to network infrastructure integrity.

Vulnerability

The vulnerability involves improper neutralization of special elements used in an OS command (CWE-78). An authenticated user with low privileges can leverage this flaw to inject malicious commands, leading to full system compromise.

Business impact

The vulnerability carries a CVSS score of 8.4, reflecting a high risk to confidentiality, integrity, and availability. Successful exploitation grants an attacker the ability to execute arbitrary code, which could result in unauthorized access to sensitive network configuration data, disruption of critical RAN services, or complete system takeover. Given the nature of these products, this could lead to widespread operational outages and potential lateral movement within the provider's management network.

Remediation

Immediate Action: Administrators must update Ericsson Site Controller 6610 to version S24.Q2 or later, and Ericsson RAN Compute to version 24.Q1.C5 or later, as specified in the vendor security advisory.

Proactive Monitoring: Security teams should monitor system access logs for unusual command-line activity, particularly patterns involving shell metacharacters or unexpected execution of administrative utilities by low-privileged service accounts.

Compensating Controls: Restrict access to the EMCLI management interface to trusted administrative segments only, and implement strict identity and access management policies to minimize the exposure of accounts capable of triggering this interface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical nature of the affected hardware in telecommunications infrastructure, this vulnerability should be prioritized for remediation. Organizations must verify their current firmware levels immediately and apply the provided vendor updates to eliminate the risk of command injection. Failure to patch these components could provide an attacker with a high-impact entry point into the management plane of the network.

More Ericsson CVEs

Sources