CVE-2025-4008

9.5 CISA KEV

Smartbedded · Meteobridge

Smartbedded Meteobridge is vulnerable to remote unauthenticated command injection via its web interface, allowing attackers to gain arbitrary command execution with root privileges.

Executive summary

A critical command injection vulnerability in Smartbedded Meteobridge is currently being exploited in the wild, enabling unauthenticated attackers to gain full root-level control of the device.

Vulnerability

The web interface of the Meteobridge system, which utilizes CGI shell scripts and C, contains an endpoint vulnerable to command injection. This flaw allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.

Business impact

This vulnerability carries a CVSS score of 9.5, reflecting its critical severity and the ease with which attackers can compromise the entire system. A successful exploit grants an attacker full root access, leading to a total loss of confidentiality, integrity, and availability. This could result in unauthorized data access, the use of the device in botnets, or total system failure, posing significant operational and security risks to the organization.

Remediation

Immediate Action: Update all affected instances of Smartbedded Meteobridge to version 6.2 or later immediately.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from the Meteobridge device and review system logs for unexpected shell commands or unauthorized modifications to system files.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block command injection patterns, although this should be treated only as a temporary measure until the firmware update is applied.

Exploitation status

Public Exploit Available: Yes, a Nuclei detection template exists.

Analyst recommendation

Given that this vulnerability is actively exploited in the wild and allows for unauthenticated root-level code execution, it represents an immediate and severe threat to any environment utilizing Smartbedded Meteobridge. All affected devices must be updated to version 6.2 or later as a matter of highest priority. If an immediate update is not feasible, the device should be isolated from the network until remediation is complete to prevent unauthorized access.

Sources

Originally found and disclosed by ONEKEY Research Labs, per the CVE Program record.