9.8
CVSSv3

CVE-2025-28236

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00145 | KEV: Not Included
Published: 18/04/2025 Updated: 22/04/2025

Vulnerability Summary

Remote Code Execution in Nautel VX Series Transmitters Firmware Update Process

Nautel VX Series transmitters running software version 6.4.0 and earlier have a remote code execution vulnerability in their firmware update mechanism. An attacker can potentially execute arbitrary code by sending a specially crafted update package to the specific software upgrades endpoint. This security issue impacts the transmitter's update process, allowing unauthorized remote code execution that could compromise the system's integrity and functionality.