Command Execution Vulnerability in Silicon Labs Products
CVE-2025-11571

2.1LOW

What is CVE-2025-11571?

A vulnerability exists in Silicon Labs products that allows for command execution through user-controlled input in JSON format via vulnerable endpoints. This flaw enables attackers on the same network to execute commands that open executables, although they cannot pass parameters or arguments. Mitigating this risk requires careful input validation and network security measures.

Affected Version(s)

Simplicity Installer tool (Silicon Labs Tool - SLT) for Simplicity Studio v6 0 <= 1.0.1

Simplicity Studio v5 0 <= 5.11.2.1

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.