Command Injection Vulnerability in OutBack Power Products
CVE-2025-24861
8.7HIGH
What is CVE-2025-24861?
A command injection vulnerability allows an attacker to send specially-crafted POST requests to OutBack Power products. This can lead to unauthorized command execution, posing risks to the integrity and confidentiality of the systems. It emphasizes the necessity for robust input validation and security practices in networked devices.
Affected Version(s)
Mojave Inverter All versions
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jon Hurtado of Sandia National Laboratory reported these vulnerabilities to CISA.