CVE-2025-48733
7.5DuraComm · SPM-500 DP-10iN-100-MU
DuraComm SPM-500 DP-10iN-100-MU devices lack necessary authentication controls, allowing unauthenticated attackers to perform unauthorized reboots of the hardware.
Executive summary
A critical authentication bypass vulnerability in DuraComm SPM-500 DP-10iN-100-MU devices allows unauthenticated remote attackers to repeatedly reboot the system, leading to significant service disruption.
Vulnerability
This flaw is classified as a missing authentication for critical function (CWE-306). It allows an unauthenticated remote attacker to trigger a device reboot, effectively enabling a denial of service condition.
Business impact
The ability for an unauthenticated user to remotely force a device reboot presents a substantial operational risk by causing persistent service outages. Given the CVSS score of 7.5, this high severity vulnerability could lead to critical system downtime and loss of availability for industrial processes that rely on these power management units.
Remediation
Immediate Action: Update the affected device to Version 4.10A by contacting DuraComm directly through their support portal to obtain the firmware package.
Proactive Monitoring: Monitor device logs for unexpected reboot events or unauthorized access attempts originating from unknown or external network segments.
Compensating Controls: Restrict network access to the management interface of the SPM-500 device using a firewall or VLAN isolation to ensure only authorized administrative workstations can communicate with the unit.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The risk of unauthorized device reboots necessitates an immediate update to version 4.10A to restore proper authentication controls. IT administrators should verify the exposure of these devices on their networks and implement strict access controls as a priority until the firmware can be applied.
More DuraComm CVEs
Sources
Originally found and disclosed by Brandon Vincent of Arizona Public Service reported these vulnerabilities to CISA., per the CVE Program record.