← back
CVE-2025-48466

Modbus Command Injection without Authentication

CVSS 8.1 HIGHEPSS 0.5%CWE-863
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
24 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →