CVE-2025-11571 is a command injection vulnerability (CWE-78) where vulnerable endpoints accept user-controlled JSON input via a URL, allowing commands to open executables without parameters. Exploitation requires the attacker to be on the same network. With a CVSS score of 2.1 (LOW), its potential impact on confidentiality and integrity is limited. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Silabs.Com | Simplicity Installer Tool (Silicon Labs Tool - SLT) For Simplicity Studio V6 | >= 0, <= 1.0.1CNA affecteddefault unaffected | |
| Silabs.Com | Simplicity Studio V5 | >= 0, <= 5.11.2.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.