CVE-2025-9229 Details
Description
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.
A vulnerability allowing information disclosure through error handling has been identified in Mobile Industrial Robots (MiR) software versions prior to 3.0.0. This vulnerability allows unauthenticated attackers to access verbose error pages that reveal detailed error information, including file paths and other sensitive data. Such information could potentially facilitate future exploitation attempts.
Users are advised to update to the latest software version, at least version 3.0.0. If an immediate update is not possible, it is recommended to operate the MiR system in a segmented and secured network with strict firewall rules and to secure user accounts on the MiR system as outlined in the MiR Cybersecurity Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mobile-industrial-robots.com/security-advisories/information-disclosure | Teradyne Robotics | |
| https://supportportal.mobile-industrial-robots.com/documentation/mir-cybersecurity-guide/mir-cybersecurity-guide/ | Teradyne Robotics | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-209 | Generation of Error Message Containing Sensitive Information | Teradyne Robotics |
Affected Products
| Product | Versions |
|---|---|
| Mobile Industrial Robots MiR | All versions |
CPE
Remediation
| |
| Mobile Industrial Robots MiR Fleet | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Teradyne Robotics |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 5, 2025 | CVE Modified | Teradyne Robotics |
| Aug 20, 2025 | New CVE Received | Teradyne Robotics |
Volerion