ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-6278
Remote OS Command Injection in GNU Bash via Crafted Environment (Shellshock-family)

GNU Bash, the standard command interpreter shipped with most Linux, Unix, and macOS systems, mishandles specially crafted environment variables, allowing attackers to inject and execute arbitrary OS commands (CVE-2014-6278 is one of the follow-on "Shellshock" parsing flaws disclosed in September 2014 alongside the original CVE-2014-6271). Exploitation requires a path where attacker-controlled data reaches Bash through the environment, classically via web CGI scripts, restricted or forced-command SSH configurations, DHCP clients, and other services that invoke the shell. A successful attack yields arbitrary command execution with the privileges of the invoking service, potentially leading to full system compromise. Any unpatched GNU Bash installation is affected, including Linux/Unix servers, macOS endpoints, and embedded or network appliances that bundle the shell. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-02, confirming exploitation in the wild, and EPSS assigns a 99.5% probability of exploitation within 30 days.

Do: Upgrade Bash to your distribution's or vendor's current patched build (all major Linux distributions and Apple shipped fixes after the September 2014 disclosures) and verify installed package versions rather than assuming patch status. Prioritize remediation on internet-facing systems where Bash may run with attacker-controlled environment variables, such as web/CGI servers, SSH forced-command setups, and embedded appliances, and follow CISA BOD 22-01 mitigation guidance per the KEV listing, or discontinue use if patches are unavailable. Hunt for legacy or embedded images that never received the 2014-era patches, since those are the most likely remaining vulnerable instances.

100% KEV
  • GNU Bash
massmillions of installations, including hundreds of thousands of internet-exposed vulnerable hosts
CVE-2015-7755
Authentication Bypass in Juniper ScreenOS Grants Remote Admin Access

CVE-2015-7755 is an improper authentication flaw (CWE-287) in Juniper ScreenOS that allows an unauthenticated remote attacker to gain administrative access to affected Juniper firewalls. It is triggered remotely via the device's administrative access path — widely reported as a hardcoded-credential backdoor reachable over SSH/Telnet management sessions, so any network that can reach the management interface is exposed. A successful attacker gains full administrator control of the firewall, enabling configuration changes, traffic manipulation, credential theft, and persistence. Only organizations running Juniper ScreenOS (legacy NetScreen/SSG firewall deployments) are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-02, confirming exploitation in the wild; no public proof-of-concept is known.

Do: Per the CISA required action and BOD 22-01, upgrade ScreenOS to a fixed release per Juniper's advisory, or if fixed versions are unavailable for your hardware, discontinue use or immediately restrict SSH and Telnet administrative access to trusted management networks. Audit device logs for unexpected administrative logins, rotate or reset administrative credentials, and treat any long-lived ScreenOS firewall as potentially compromised given the backdoor history and current KEV listing.

61% KEV
  • Juniper ScreenOS
largeOrder of 10,000+ internet-exposed ScreenOS administrative interfaces (tens of thousands of legacy firewalls)
CVE-2017-1000353
Unauthenticated Deserialization RCE in Jenkins CLI (≤2.56 / ≤2.46.1 LTS)

CVE-2017-1000353 is an unauthenticated remote code execution flaw in the Jenkins CLI (CWE-502): an attacker can send a crafted serialized Java SignedObject to the remoting-based CLI endpoint, where it is deserialized with a new ObjectInputStream and bypasses Jenkins' existing blacklist-based deserialization protection. Triggering it requires only network reachability to the Jenkins remoting CLI — no authentication or user interaction — which is why the flaw scores 9.8 (critical) under CVSS 3.1. Successful exploitation gives arbitrary code execution with the privileges of the Jenkins process, i.e., full control of the CI/CD server and any credentials, source code, and build infrastructure it holds; Jenkins servers have historically been targeted for cryptomining campaigns such as JenkinsMiner, which reportedly generated $3.4 million. All Jenkins versions 2.56 and earlier and 2.46.1 LTS and earlier are affected, including Oracle Communications Cloud Native Core Automated Test Suite deployments that bundle affected Jenkins releases. Exploitation status is serious: a public proof-of-concept exploit exists (Exploit-DB 41965), EPSS estimates a 99.7% probability of exploitation within 30 days, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-02.

Do: Upgrade to Jenkins 2.57 or later (weekly line) or 2.46.2 LTS or later, which add SignedObject to the deserialization blacklist, backport the HTTP CLI protocol, and deprecate/disable the remoting (Java serialization) CLI by default; as an interim mitigation, disable or restrict access to the remoting CLI (e.g., the /cli endpoint) from untrusted networks. Because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations or discontinue use per BOD 22-01, and all administrators of internet-facing Jenkins instances should check for signs of compromise such as cryptomining processes. Oracle Communications Cloud Native Core Automated Test Suite users should apply the applicable Oracle security patch/update addressing CVE-2017-1000353.

9.8100% KEV PoC
  • Jenkins (open-source automation server) 2.56 and earlier (weekly line); 2.46.1 LTS and earlier (LTS line)
  • Oracle Communications Cloud Native Core Automated Test Suite affected when bundling Jenkins 2.56 or earlier / 2.46.1 LTS or earlier; bundled Jenkins version range not specified in the source data
mass≈1,000,000+ users / hundreds of thousands of installations, with tens of thousands of instances historically exposed to the internet
CVE-2025-21043
Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so)

CVE-2025-21043 is an out-of-bounds write vulnerability (CWE-787) in libimagecodec.quram.so, the image-decoding library used by Samsung Mobile Devices. It can be triggered remotely when the vulnerable codec processes maliciously crafted image data, and per the CVSS vector it requires no privileges or user interaction. A successful attack allows a remote attacker to execute arbitrary code on the device with high impact on confidentiality, integrity, and availability (CVSS 9.8, critical). All Samsung mobile devices running a security update prior to the September 2025 Maintenance Release (SMR Sep-2025 Release 1) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of October 2, 2025, indicating exploitation in the wild, and headlines note Samsung patched it as an actively exploited zero-day; a related Samsung image-codec zero-day (CVE-2025-21042) was used to deliver LANDFALL spyware.

Do: Update affected Samsung devices to SMR Sep-2025 Release 1 or later via Settings > Software update, prioritizing devices exposed to untrusted image content (messaging, email, browsers). CISA KEV requires applying the vendor fix (or discontinuing use) under BOD 22-01 timelines for federal systems. Because exploitation has been observed in the wild and a related image-codec zero-day (CVE-2025-21042) was used to deploy LANDFALL spyware, verify fleet patch levels and investigate any devices showing signs of spyware infection.

9.82% KEV
  • Samsung Mobile Devices (libimagecodec.quram.so, Android) All Samsung Mobile Devices with security updates prior to SMR Sep-2025 Release 1
masshundreds of millions to over 1 billion Samsung mobile devices (any device not yet on SMR Sep-2025 Release 1)
CVE-2025-4008
Unauthenticated Command Injection RCE in Smartbedded Meteobridge

The Meteobridge web interface, implemented in CGI shell scripts and C, exposes an endpoint vulnerable to command injection (CWE-77) with missing authentication requirements (CWE-306). A remote, unauthenticated attacker who can reach the web interface can supply crafted input that is passed to the underlying shell, gaining arbitrary command execution with root privileges on the device. Affected products are Smartbedded Meteobridge firmware and the Meteobridge VM, used to bridge weather-station data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-02, and public reporting indicates it is being actively exploited in the wild; EPSS puts the 30-day exploitation probability at 93.7%. Exploitation details are documented in a public advisory by the discovering researcher (oneKey).

Do: Apply the fix or mitigations per the Smartbedded vendor instructions referenced in the CISA KEV entry (fixed version numbers are not specified in the source data, so consult the vendor advisory and the oneKey write-up before upgrading). Until patched, do not expose the Meteobridge web interface directly to the internet — restrict it to trusted management networks or via VPN/firewall rules — and check exposed instances for signs of compromise given confirmed in-the-wild exploitation. Organizations under BOD 22-01 must apply the required mitigations within the mandated timeframe or discontinue use of the product.

8.794% KEV PoC
  • Smartbedded Meteobridge firmware
  • Smartbedded Meteobridge VM
moderate≈1,000–10,000 internet-exposed Meteobridge instances (public scans historically show low thousands of exposed Meteobridge web interfaces; total installed base,…
Full article440 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 03, 2025Vulnerability / IoT Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting Smartbedded Meteobridge to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, CVE-2025-4008 (CVSS score: 8.7), is a case of command injection in the Meteobridge web interface that could result in code execution.

"Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices," CISA Said.

According to ONEKEY, which discovered and reported the issue in late February 2025, the Meteobridge web interface lets an administrator manage their weather station data collection and control the system through a web application written in CGI shell scripts and C.

Specifically, the web interface exposes a "template.cgi" script through "/cgi-bin/template.cgi," which is vulnerable to command injection stemming from the insecure use of eval calls, allowing an attacker to supply specially crafted requests to execute arbitrary code -

curl -i -u meteobridge: meteobridge \
'https://192.168.88.138/cgi-bin/template.cgi?$(id>/tmp/a)=whatever'

Furthermore, ONEKEY said the vulnerability can be exploited by unauthenticated attackers due to the fact that the CGI script is hosted in a public directory without requiring any authentication.

"Remote exploitation through a malicious webpage is also possible since it's a GET request without any kind of custom header or token parameter," security researcher Quentin Kaiser noted back in May. "Just send a link to your victim and create img tags with the src set to 'https://subnet.a/public/template.cgi?templatefile=$(command).'"

There are currently no public reports referencing how CVE-2025-4008 is being exploited in the wild. The vulnerability was addressed in Meteobridge version 6.2, released on May 13, 2025.

Also added by CISA to the KEV catalog are four other flaws -

  • CVE-2025-21043 (CVSS score: 8.8) - Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so that could allow remote attackers to execute arbitrary code.
  • CVE-2017-1000353 (CVSS score: 9.8) - Jenkins contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution, bypassing denylist-based protection mechanisms.
  • CVE-2015-7755 (CVSS score: 9.8) - Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
  • CVE-2014-6278, aka Shellshock (CVSS score: 8.8) - GNU Bash contains an OS command injection vulnerability that could allow remote attackers to execute arbitrary commands via a crafted environment.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary updates by October 23, 2025, for optimal protection.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/10/cisa-flags-meteobridge-cve-2025-4008.html