Privilege Escalation on TropOS 4th Gen Devices by Hitachi Energy
CVE-2025-1037

7.5HIGH

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
28 October 2025

What is CVE-2025-1037?

Authenticated users with the capability to execute user-level shell commands on TropOS 4th Gen devices can inadvertently gain unrestricted root access through SSH. This vulnerability arises from specific configuration modifications that allow certain scripts and executables to be run as root, exposing the system to potential exploits and unauthorized control.

Affected Version(s)

TropOS 4th Gen 8.7.0.0 <= 8.9.6.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.