CVE-2025-36729
7.2RACOM · M!DGE2
A privilege management flaw in RACOM M!DGE2 allows authenticated web interface administrators to view the master admin password and escalate their own privileges to root shell access.
Executive summary
A critical privilege escalation vulnerability in RACOM M!DGE2 allows authenticated administrators to bypass restricted access, resulting in full system compromise.
Vulnerability
This is an improper privilege management vulnerability (CWE-269) that allows an authenticated user with web interface administrator rights to access sensitive configuration data, including the master password, and elevate their own account to root shell access.
Business impact
The ability for a restricted administrator to obtain the master password and gain root shell access presents a severe security risk. This flaw could lead to complete device takeover, unauthorized modification of network configurations, and the persistent compromise of critical infrastructure, justifying the 7.2 CVSS score.
Remediation
Immediate Action: Review the official RACOM security advisory for the availability of a patched firmware version and apply it to all affected M!DGE2 units immediately.
Proactive Monitoring: Monitor device access logs for unauthorized attempts to escalate privileges or unexpected modification of administrative account configurations.
Compensating Controls: Restrict access to the web administration interface to trusted networks or specific management workstations to minimize the attack surface until a patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total system compromise, this vulnerability poses a significant risk to operational integrity. Administrators should prioritize identifying all vulnerable M!DGE2 devices and apply the necessary firmware updates as soon as they are made available by the vendor to prevent unauthorized privilege escalation and system takeover.
Sources
Originally found and disclosed by Derrie Sutton, Giulio Lyons, per the CVE Program record.