PT-2025-43628 · Emoncms · Emoncms

Published

2025-10-24

·

Updated

2025-10-24

·

CVE-2025-60938

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emoncms version 11.7.3
Description Emoncms version 11.7.3 contains a remote code execution issue in the firmware upload functionality. Authenticated users can execute arbitrary commands on the system. This is due to inadequate validation of user-supplied input, specifically the filename, port, baud rate, core, and autoreset parameters. The vulnerability is present in the /admin/upload-custom-firmware API endpoint.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /admin/upload-custom-firmware API endpoint.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-60938

Affected Products

Emoncms