Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9094

Опубликовано: 17 авг. 2025
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."

EPSS

Процентиль: 6%
0.00029
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-791

Связанные уязвимости

CVSS3: 4.3
github
6 дней назад

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."

EPSS

Процентиль: 6%
0.00029
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-791