Command Injection Vulnerability in TropOS 4th Gen Device by Hitachi Energy
CVE-2025-1038
7.5HIGH
What is CVE-2025-1038?
The Diagnostics Tools page in the TropOS 4th Gen's web-based configuration utility lacks proper validation for user-controlled input. This flaw enables authenticated users with elevated privileges to inject arbitrary commands into the device's command shell. The executed commands can manipulate several set-uid (SUID) applications, potentially granting unauthorized root access to the system. This vulnerability poses significant security risks, allowing potential attackers to exploit the device's capabilities maliciously.
Affected Version(s)
TropOS 4th Gen 8.7.0.0 < 8.9.6.0