CVE-2025-41378 Details
Description
The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.
A command injection vulnerability has been identified in the Intellian Technologies Iridium Certus 700 satellite communication system, specifically in version 1.0.1. The issue arises because the SSID field is not properly parsed, allowing attackers to inject commands that are executed on the hostpad.conf file. This vulnerability could be exploited to gain additional knowledge about the system and potentially compromise other connected devices. Furthermore, the injected information could be obscured by the web panel's logging function, making detection more challenging.
Users are advised to update to the Q2 2025 release, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 23, 2025CISA-ADP
Assessed May 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-intellian-technologies-iridium-certus | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intellian Iridium Certus 700 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 23, 2025 | New CVE Received | [email protected] |
Volerion