CVE-2025-48466
Modbus Command Injection without Authentication
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.1EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
24 jun 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Productos afectados
Advantech · Advantech Wireless Sensing and Equipment (WISE)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →