CVE 6.6 MEDIUM

Supermicro BMC firmware update validation bypass_CVE-2025-7937

6.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.

Basic Information

ID CVE-2025-7937
Source Supermicro
Published Sep 19, 2025 at 02:09

Affected Product

Vendor SMCI
Product MBD-X12STW
Version 01.06.17
Affected Versions SMCI MBD-X12STW 01.06.17

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.