# CVE-2025-52548

## Summary

- **CVE ID:** CVE-2025-52548
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1242
- **Published:** Sep 2, 2025
- **Last Modified:** Mar 13, 2026

## Description

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.

## Affected Products

- Copeland LP — E3 Supervisory Control (0)

## References

- [CNA](https://www.armis.com/research/frostbyte10/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 27.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._