OS Command Injection Vulnerability in Vitogate 300 by Carrier
CVE-2025-9494

8.5HIGH

Key Information:

Vendor

Viessmann

Vendor
CVE Published:
23 September 2025

What is CVE-2025-9494?

An OS command injection vulnerability exists in the Vitogate 300 product, allowing attackers to exploit the /cgi-bin/vitogate.cgi endpoint. This issue arises when the form JSON parameter is improperly sanitized, enabling authenticated users to inject malicious OS commands. Through this vulnerability, attackers can execute arbitrary commands on the affected devices, potentially compromising the security and integrity of the installation.

Affected Version(s)

Vitogate 300 1 < 3.1.0.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adhkr of LuwakLab working with Trend Micro Zero Day Initiative
.
CVE-2025-9494 : OS Command Injection Vulnerability in Vitogate 300 by Carrier