CVE-2025-40837 Details
Description
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.
A missing authorization vulnerability has been identified in Ericsson Indoor Connect version 8855. This vulnerability can be exploited to gain access to the system with higher privileges than intended.
Users are advised to upgrade to Ericsson Indoor Connect version 2025.Q2, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ericsson.com/en/about-us/security/psirt/e2025-09-25 | Ericsson | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | Ericsson |
Affected Products
| Product | Versions |
|---|---|
| ericsson indoor connect 8855 firmware | < 2025.q2 |
CPE
Remediation
| |
| ericsson indoor connect 8855 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Ericsson |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Initial Analysis | [email protected] |
| Sep 30, 2025 | CVE Modified | Ericsson |
| Sep 25, 2025 | New CVE Received | Ericsson |