« Volver al listado

CVE-2025-48469

Estado: AnalizadaCrítica (9.6)—

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A (red adyacente), acceso no autenticado a página de actualización. Carga de firmware malicioso permite backdoor (persistencia con T1556.004/T1547.013) y escalada de privilegios (T1068).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-48469",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-48469",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-24T15:13:31.341676Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
      "affectedData": [
        {
          "vendor": "Advantech",
          "product": "Advantech Wireless Sensing and Equipment (WISE)",
          "versions": [
            {
              "status": "affected",
              "version": "A2.01 B00"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-06-24T03:15:34.390",
  "references": [
    {
      "url": "https://jro.sg/CVEs/CVE-2025-48469/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
    },
    {
      "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-061/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation."
    },
    {
      "lang": "es",
      "value": "La explotación exitosa de la vulnerabilidad podría permitir que un atacante no autenticado cargue firmware a través de una página de actualización pública, lo que podría conducir a la instalación de una puerta trasera o a una escalada de privilegios."
    }
  ],
  "lastModified": "2026-06-17T09:29:40.190",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:advantech:wise-4060lan_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40764D08-8173-4AF3-BB93-249D12A9D07D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:advantech:wise-4060lan:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E7DCE031-021A-47BC-B81C-1B0DCB9EB8F1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:advantech:wise-4050lan_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CFD6963-E219-48F1-8BDE-C3D9F6B2091B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:advantech:wise-4050lan:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "72DFF800-1684-4038-BB79-C679DCAF4105"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:advantech:wise-4010lan_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87715BBD-E9A9-404A-B11E-CFCE0E4CA409"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:advantech:wise-4010lan:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9241107A-6586-475F-AE13-C541F9AE8AE6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}