PT-2025-39396 · Ericsson · Ericsson Indoor Connect 8855
Telstra
·
Published
2025-09-25
·
Updated
2025-09-30
·
CVE-2025-40836
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ericsson Indoor Connect 8855 (affected versions not specified)
Description
The software contains an improper input validation issue. Successful exploitation could result in a loss of data integrity and confidentiality, potentially leading to unauthorized disclosure and modification of user and configuration data. It may also be possible to execute commands with escalated privileges, impact service availability, and modify system files and configuration data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ericsson Indoor Connect 8855