Command Injection Vulnerability in Alpine iLX-507 Devices
CVE-2025-8473

6.4MEDIUM

Key Information:

Vendor

Alpine

Status
Vendor
CVE Published:
1 August 2025

What is CVE-2025-8473?

The command injection vulnerability in Alpine iLX-507 devices allows attackers to execute arbitrary code due to insufficient validation of user-supplied input in the UPDM_wstpCBCUpdStart function. This exploit can be executed by attackers who have physical access to the devices, as authentication is not required to initiate the attack. The risk is particularly concerning as it allows execution of code with root privileges, potentially compromising the entire system.

Affected Version(s)

iLX-507 6.0.000

References

CVSS V3.0

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8473 : Command Injection Vulnerability in Alpine iLX-507 Devices