CVE-2025-7937 describes a critical vulnerability in the Supermicro BMC firmware validation logic, specifically affecting the Supermicro MBD-X12STW. An attacker with high privileges can exploit this flaw to install specially crafted, malicious firmware, leading to complete compromise of the BMC. With a CVSS score of 7.2 (HIGH), this vulnerability allows for remote code execution with high impact on confidentiality, integrity, and availability. While there is no public exploit code or KEV listing, the vulnerability has garnered significant community attention and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SMCI | MBD-X12STW | 01.06.17CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.