CVE-2025-4008

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

Scoring

Severity
HIGH
CVSS base score
8.7
CVSS vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
93.67%
CISA KEV
Known exploited vulnerability
CWE
CWE-77, CWE-306
Published
2025-05-21
Last modified
2026-02-26

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs