Privilege Escalation Issue in saTECH BCU Firmware by saTECH
CVE-2025-2858

8.5HIGH

Key Information:

Vendor

Arteche

Vendor
CVE Published:
28 March 2025

What is CVE-2025-2858?

A privilege escalation vulnerability exists in the saTECH BCU firmware version 2.1.3. This flaw allows an attacker with command line interface (CLI) access to exploit the 'nice' command, enabling them to bypass all imposed restrictions and gain superuser privileges. This type of vulnerability poses significant risks as it could lead to unauthorized access and control over the affected devices, potentially compromising critical operations.

Affected Version(s)

saTECH BCU 2.1.3

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AarĂłn Flecha
Gabriel VĂ­a Echezarreta
.