PT-2025-36721 · Smseagle · Smseagle

Vincent Salvadori

·

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-10095

CVSS v4.0

5.3

Medium

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: SMSEagle versions prior to 6.11
Description: A SQL injection vulnerability exists in the SMPP server component of the SMSEagle firmware. The issue stems from improper sanitization of user input in the server's scripts during database interactions. This vulnerability is isolated to the SMPP server and its dedicated database, limiting the scope of impact to SMPP server operations.
Recommendations: Update to version 6.11 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10095

Affected Products

Smseagle