CVE-2025-8748
8.8Mobile Industrial Robots · MiR Robots and MiR Fleet
Mobile Industrial Robots software versions prior to 3.0.0 are vulnerable to OS command injection, allowing authenticated users to execute arbitrary commands via crafted HTTP requests.
Executive summary
A critical command injection vulnerability in Mobile Industrial Robots software allows authenticated attackers to execute arbitrary system commands, posing a severe risk of unauthorized control.
Vulnerability
This flaw is an OS command injection (CWE-78) occurring within the software interface. It requires the attacker to be an authenticated user, who can then trigger the vulnerability by sending a specially crafted HTTP request to the target system.
Business impact
The ability to execute arbitrary commands on the underlying operating system provides an attacker with full control over the affected industrial robot or fleet management system. Given the CVSS score of 8.8, this vulnerability carries a high risk of total system compromise, potentially leading to operational disruption, loss of process integrity, or unauthorized access to sensitive internal network segments.
Remediation
Immediate Action: Update all MiR Robots and MiR Fleet instances to software version 3.0.0 or the latest available release provided by the vendor.
Proactive Monitoring: Monitor system logs for suspicious HTTP requests containing shell metacharacters or unexpected system calls originating from authenticated user accounts.
Compensating Controls: Implement strict network segmentation to isolate robot management interfaces and enforce robust access control policies to limit the number of users capable of interacting with the system.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this command injection vulnerability necessitates prompt attention to prevent unauthorized system control. Administrators must prioritize updating all affected MiR software to version 3.0.0 or later to eliminate the underlying injection vector and secure the environment against potential exploitation.
More Mobile Industrial Robots CVEs
Sources
Originally found and disclosed by Lockheed Martin Red Team, per the CVE Program record.