CVE-2025-27262 Details
Description
Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.
A command injection vulnerability has been identified in Ericsson Indoor Connect version 8855. This vulnerability allows for unauthorized execution of commands, which could be done with escalated privileges. Exploitation of this vulnerability may lead to a loss of integrity and confidentiality, unauthorized disclosure and modification of user and configuration data, disruption of service availability, and unauthorized changes to system files and configuration data.
Users are advised to upgrade to Ericsson Indoor Connect version 2025.Q2, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ericsson.com/en/about-us/security/psirt/e2025-09-25 | Ericsson | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Ericsson |
Affected Products
| Product | Versions |
|---|---|
| ericsson indoor connect 8855 firmware | < 2025.q2 |
CPE
Remediation
| |
| ericsson indoor connect 8855 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Ericsson |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Initial Analysis | [email protected] |
| Sep 30, 2025 | CVE Modified | Ericsson |
| Sep 25, 2025 | New CVE Received | Ericsson |