PT-2025-42791 · Microchip · Microchip Timeprovider 4100
Andrea Sindoni
+8
·
Published
2025-10-20
·
Updated
2025-10-23
·
CVE-2025-47900
CVSS v4.0
8.9
High
| Vector | AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Microchip Time Provider 4100 versions prior to 2.5
Description
An improper neutralization of special elements used in an OS command vulnerability exists in Microchip Time Provider 4100, allowing for OS command injection. This issue relates to remote code execution through the backup configuration password.
Recommendations
Update to a version newer than 2.5.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microchip Timeprovider 4100