CVE-2025-14097 Details
Description
A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management when specific internal conditions are met. Exploitation requires that a remote connection is established with additional information obtained through other means. The issue is caused by a weakness in the analyzer’s application software. Other related CVE's are CVE-2025-14095 & CVE-2025-14096. Affected customers have been informed about this vulnerability. This CVE is being published to provide transparency. Required Configuration for Exposure: Affected application software version is in use and remote support feature is enabled in the analyzer. Temporary work Around: If the network is not considered secure, please remove the analyzer from the network. Permanent solution: Customers should ensure the following: • The network is secure, and access follows best practices. Local Radiometer representatives will contact all affected customers to discuss a permanent solution. Exploit Status: Researchers have provided working proof-of-concept (PoC). Radiometer is not aware of any publicly available exploits at the time of this publication.
A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management under specific internal conditions. Exploitation requires an established remote connection, with additional information obtained through other means. The issue stems from a weakness in the analyzer's application software. Affected customers have been informed about this vulnerability. This CVE is being published to provide transparency.
Customers should ensure their network is secure and follows best practices. Local Radiometer representatives will contact affected customers to discuss a permanent solution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 17, 2025CISA-ADP
Assessed Dec 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.radiometer.com/myradiometer | Radiometer | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | Radiometer |
Affected Products
| Product | Versions |
|---|---|
| Radiometer ABL800 FLEX | All versions |
CPE
Remediation
| |
| Radiometer ABL90 FLEX PLUS | All versions |
CPE
Remediation
| |
| Radiometer AQT90 FLEX | All versions |
CPE
Remediation
| |
| Radiometer TCM5 FLEX | All versions |
CPE
Remediation
| |
| Radiometer PeriFlux 6000 | All versions |
CPE
Remediation
| |
| Radiometer AQURE | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Radiometer |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 17, 2025 | New CVE Received | Radiometer |
Volerion