CVE-2025-52548 Details
Description
E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
A vulnerability exists in E3 Site Supervisor Control firmware versions prior to 2.31F01, where a hidden API call in the application services can be exploited by an attacker with admin access. This API enables SSH and Shellinabox, providing remote access to the underlying operating system, even though these services are disabled by default.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.armis.com/research/frostbyte10/ | Armis | MitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1242 | Inclusion of Undocumented Features or Chicken Bits | Armis |
Affected Products
| Product | Versions |
|---|---|
| copeland e3 supervisory controller firmware | < 2.31f01 |
CPE
Remediation
| |
| copeland site supervisor bx 860-1240 | All versions |
CPE
Remediation
| |
| copeland site supervisor bxe 860-1245 | All versions |
CPE
Remediation
| |
| copeland site supervisor cx 860-1260 | All versions |
CPE
Remediation
| |
| copeland site supervisor cxe 860-1265 | All versions |
CPE
Remediation
| |
| copeland site supervisor rx 860-1220 | All versions |
CPE
Remediation
| |
| copeland site supervisor rxe 860-1225 | All versions |
CPE
Remediation
| |
| copeland site supervisor sf 860-1200 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Armis |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 1, 2025 | Initial Analysis | [email protected] |
| Sep 2, 2025 | New CVE Received | Armis |