CVE-2025-9494 describes an OS command injection vulnerability in the Vitogate 300, specifically within the /cgi-bin/vitogate.cgi endpoint when the 'form' JSON parameter is set to 'form-0-2'. This flaw allows an authenticated attacker to inject arbitrary OS commands due to improper input sanitization before being passed to popen(). The vulnerability carries a high CVSS score of 8.5, indicating a significant risk of compromise, including high impact to confidentiality, integrity, and availability, with an attack vector requiring network access and high privileges. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Viessmann | Vitogate 300 | >= 1, < 3.1.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.