PT-2025-36721 · Smseagle · Smseagle
Vincent Salvadori
·
Published
2025-09-09
·
Updated
2025-09-09
·
CVE-2025-10095
CVSS v4.0
5.3
Medium
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
SMSEagle versions prior to 6.11
Description:
A SQL injection vulnerability exists in the SMPP server component of the SMSEagle firmware. The issue stems from improper sanitization of user input in the server's scripts during database interactions. This vulnerability is isolated to the SMPP server and its dedicated database, limiting the scope of impact to SMPP server operations.
Recommendations:
Update to version 6.11 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smseagle