CVE-2025-52548
E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.34%
- CWE
- CWE-1242
- Published
- 2025-09-02
- Last modified
- 2026-03-13
Affected products
- Copeland LP E3 Supervisory Control
Weakness type
Related vulnerabilities
- CVE-2023-3634 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions
- CVE-2025-41756 — Arbitrary Write with ubr-editfile
- CVE-2025-41754 — Arbitrary Read with ubr-editfile
- CVE-2026-24714 — Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic...
- CVE-2021-4469 — Denver SHO-110 IP Camera Unauthenticated Snapshot Access
- CVE-2025-12176 — Undocumented Administrative Accounts
- CVE-2017-20204 — DBLTek GoIP Telnet Admin Interface Undocumented Backdoor
- CVE-2025-55050 — CWE-1242: Inclusion of Undocumented Features