Command Injection Vulnerability in Alpine iLX-507 Devices
CVE-2025-8473
6.6MEDIUM
What is CVE-2025-8473?
The command injection vulnerability in Alpine iLX-507 devices allows attackers to execute arbitrary code due to insufficient validation of user-supplied input in the UPDM_wstpCBCUpdStart function. This exploit can be executed by attackers who have physical access to the devices, as authentication is not required to initiate the attack. The risk is particularly concerning as it allows execution of code with root privileges, potentially compromising the entire system.
Affected Version(s)
iLX-507 6.0.000
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved