CVE-2025-48466
Modbus Command Injection without Authentication
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected products
Advantech · Advantech Wireless Sensing and Equipment (WISE)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →