CVE 8.5 HIGH

Ericsson Indoor Connect 8855 – Improper Neutralization of Special Elements used in an OS Command Vulnerability_CVE-2025-27262

8.5 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Ericsson
Indoor Connect 8855 contains a command injection vulnerability which if
exploited can lead to loss of integrity and confidentiality, as well as
unauthorized disclosure and modification of user and configuration data. It
may also be possible to execute commands with escalated privileges, impact
service availability, as well as modify system files and configuration
data.

Basic Information

ID CVE-2025-27262
Source ERIC
Published Sep 25, 2025 at 14:43
Modified Sep 25, 2025 at 15:27

Affected Product

Vendor Ericsson
Product Indoor Connect 8855
Affected Versions Ericsson Indoor Connect 8855 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.