The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a high-severity command injection vulnerability in Smartbedded Meteobridge devices, tracked as CVE-2025-4008, and added it to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. This vulnerability, with a CVSS score of 8.7, resides in the Meteobridge web interface, specifically within the publicly accessible 'template.cgi' script, which is written in CGI shell scripts and C. The flaw allows remote, unauthenticated attackers to execute arbitrary commands with root privileges by sending specially crafted GET requests to the vulnerable endpoint. Security researchers from ONEKEY discovered that the vulnerability stems from insecure use of eval calls in the CGI script, enabling attackers to inject commands without any authentication or custom headers. The attack can be triggered simply by enticing a victim to visit a malicious webpage or by directly targeting exposed devices, as the CGI script is accessible without authentication. CISA’s advisory highlights that this vulnerability is being actively exploited in the wild, although no detailed public reports of exploitation techniques have been released. The vulnerability was addressed by Smartbedded in Meteobridge version 6.2, released on May 13, 2025, and users are strongly urged to update to this version to mitigate the risk. CISA’s inclusion of CVE-2025-4008 in the KEV catalog mandates that Federal Civilian Executive Branch (FCEB) agencies remediate the vulnerability by a specified due date, as per Binding Operational Directive (BOD) 22-01. The directive also encourages all organizations, not just federal agencies, to prioritize patching of KEV-listed vulnerabilities to reduce exposure to cyberattacks. The vulnerability is considered a significant risk to both federal and enterprise environments due to its ease of exploitation and the potential for attackers to gain full control of affected devices. Alongside Meteobridge, CISA’s recent KEV catalog update also included critical vulnerabilities in products from GNU Bash, Juniper, Samsung, and Jenkins, underscoring the ongoing threat posed by actively exploited flaws. The technical details provided by security researchers demonstrate that exploitation does not require advanced skills, increasing the urgency for immediate remediation. Organizations using Meteobridge devices should verify their firmware version and apply the latest updates without delay. The public advisories and catalog updates serve as a warning to the broader cybersecurity community about the importance of monitoring and addressing vulnerabilities that are known to be under active attack. Failure to remediate CVE-2025-4008 could result in unauthorized access, data compromise, or further exploitation within affected networks. CISA continues to monitor and update the KEV catalog as new evidence of exploitation emerges, reinforcing the need for proactive vulnerability management.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Following the KEV catalog update, CISA required federal civilian agencies to remediate the newly listed vulnerabilities by this deadline under Binding Operational Directive 22-01.
CISA added five known exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including Smartbedded Meteobridge CVE-2025-4008 alongside flaws affecting Samsung mobile devices, Jenkins, Juniper ScreenOS, and GNU Bash. The addition indicates evidence of active exploitation in the wild.
Smartbedded released Meteobridge version 6.2 to fix CVE-2025-4008, a high-severity command injection flaw in the template.cgi web interface that could allow unauthenticated remote code execution as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcethecyberthrone.in
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.