CVE-2025-7937 DetailsANALYZED This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.
Description There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.
A vulnerability exists in the Supermicro BMC firmware validation logic on the MBD-X12STW motherboard. This issue allows an attacker to bypass the firmware verification process and update the system firmware with a specially crafted image. The manipulated image can redirect the firmware update process to a fake table in the unsigned region, exploiting the improper verification of cryptographic signatures.
Affected Supermicro motherboard SKUs will require a BMC update to address this vulnerability. An updated BMC firmware is being tested and validated by Supermicro. Please check the Release notes for the resolution.
Show AI summary Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 19, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Total
CISA-ADP
Assessed Sep 20, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration CWE-ID CWE Name Source CWE-347 Improper Verification of Cryptographic Signature Super Micro Computer, Inc.
Affected Products Product Versions Supermicro MBD-X12STW All versions
CPE cpe:2.3:o:supermicro:x12stw-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stw-f:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stw-tf_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stw-tf:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stn-c:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stn-c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12std-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12std-f:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12scv-w:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12scv-w_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stn-e:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stn-e_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stn-h:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stn-h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12sth-sys_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12sth-sys:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stn-l:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stn-l_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12scq:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12scq_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12sth-f:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12sth-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12spw-f:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12spw-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12ste-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12ste-f:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12ddw-a6:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12ddw-a6_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stl-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stl-f:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12scz-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12scz-f:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12qch+_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12dsc-6:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12qch+:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12stl-if_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12stl-if:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12dsc-6_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12spo-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12spo-f:*:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x12sae:*:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x12sae_firmware:*:*:*:*:*:*:*:*
Change History 4 change records found show changes
Date Action Recorded By Jun 17, 2026 CVE Modified Super Micro Computer, Inc. Jun 17, 2026 CVE Modified CISA-ADP Sep 25, 2025 CVE Modified Super Micro Computer, Inc. Sep 19, 2025 New CVE Received Super Micro Computer, Inc.