PT-2025-39396 · Ericsson · Ericsson Indoor Connect 8855

Telstra

·

Published

2025-09-25

·

Updated

2025-09-30

·

CVE-2025-40836

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ericsson Indoor Connect 8855 (affected versions not specified)
Description The software contains an improper input validation issue. Successful exploitation could result in a loss of data integrity and confidentiality, potentially leading to unauthorized disclosure and modification of user and configuration data. It may also be possible to execute commands with escalated privileges, impact service availability, and modify system files and configuration data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-40836

Affected Products

Ericsson Indoor Connect 8855