CVE 6.9 MEDIUM

Enabling SSH and Shellinabox on the vulnerable machine_CVE-2025-52548

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.

Basic Information

ID CVE-2025-52548
Source Armis
Published Sep 2, 2025 at 11:26

Affected Product

Vendor Copeland LP
Product E3 Supervisory Control
Affected Versions Copeland LP E3 Supervisory Control 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.