7.5

CVE-2025-27260

Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability

Ericsson
Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special
Elements vulnerability which, if exploited, can lead to unauthorized
modification of certain information
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EricssonIndoor Connect 8855 Firmware Version < 2025.q3
   EricssonIndoor Connect 8855 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
85b1779b-6ecd-4f52-bcc5-73eac4659dcf 7.2 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-790 Improper Filtering of Special Elements

The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.

https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-indoorconnect-march-2026
Vendor Advisory
https://www.ericsson.com/en/about-us/security/psirt/CVE-2025-27260
Vendor Advisory