8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.
Basic Information
ID
CVE-2025-41451
Source
Danfoss
Published
Aug 22, 2025 at 02:40
Affected Product
Vendor
Danfoss
Product
AK-SM8xxA Series
Affected Versions
Danfoss AK-SM8xxA Series 0