CVE-2025-28236 Details
Description
Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.
A remote code execution vulnerability has been identified in the Nautel VX Series transmitters running firmware versions through 6.4.0. This vulnerability arises from the absence of digital signature verification in the firmware update process, allowing attackers to upload crafted update packages via the '/#/software/upgrades' endpoint. Exploitation of this vulnerability enables unauthorized execution of arbitrary code with root privileges on the affected device.
Nautel should implement digital signature verification for firmware updates, ensuring that all update packages are cryptographically signed and validated before installation. Additionally, access to the software upload process should be restricted to authorized users only, possibly through multi-factor authentication. Integrity checks, such as SHA256 hash validation, could be employed to detect modifications in firmware before installation. Finally, execution permissions on update scripts should be limited to prevent arbitrary script execution from firmware packages.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 18, 2025CISA-ADP
Assessed Apr 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28236 | CISA-ADP | ExploitRemedyTechnical Analysis |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28236 | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-494 | Download of Code Without Integrity Check | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Nautel VX SW | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2025 | CVE Modified | CISA-ADP |
| Apr 18, 2025 | New CVE Received | [email protected] |
Volerion