Smartbedded Meteobridge devices have been found to contain a critical command injection vulnerability, tracked as CVE-2025-4008, which affects the management web interface endpoint /public/template.cgi. The flaw arises from improper neutralization of user-supplied input, which is parsed and used unsanitized in an eval call, allowing for remote (adjacent), unauthenticated attackers to execute arbitrary commands with root privileges. This vulnerability has been rated as high severity, with a CVSS score of 8.8, and there is confirmed evidence of active exploitation in the wild. Devices running Meteobridge versions prior to 6.2 are vulnerable to this exploit, making a significant number of systems potentially at risk if not updated. Successful exploitation could result in complete system compromise, giving attackers full control over the affected device. In response, Smartbedded has released an update, and users are strongly encouraged to upgrade to version 6.2 or later to mitigate the risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recognized the seriousness of this vulnerability by adding CVE-2025-4008 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the need for immediate remediation. CISA’s inclusion of this flaw in the KEV catalog underscores the active threat it poses to organizations and individuals using Meteobridge devices. Security researchers have provided guidance on how to identify potentially vulnerable systems, including specific queries that can be used to locate affected assets within network inventories. The vulnerability is part of a broader set of flaws added to the KEV catalog, but CVE-2025-4008 is specifically noted for its active exploitation and potential for severe impact. Organizations are advised to prioritize patching and to review their inventories for any exposed Meteobridge devices. The disclosure and subsequent response demonstrate the ongoing risks associated with IoT and network management devices, which often have elevated privileges and are attractive targets for attackers. The rapid addition of this vulnerability to the KEV catalog reflects the urgency with which defenders must act to prevent compromise. The technical details of the vulnerability, including the use of unsanitized input in an eval call, highlight the importance of secure coding practices in web interfaces. The incident serves as a reminder for organizations to maintain up-to-date patching processes and to monitor advisories from both vendors and government agencies. Failure to address this vulnerability could result in attackers leveraging compromised Meteobridge devices as footholds for further attacks within a network. The situation remains dynamic, with ongoing monitoring recommended to detect any signs of exploitation or compromise related to this vulnerability.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
RunZero published technical guidance on how defenders can find Smartbedded Meteobridge devices on their networks in response to the actively exploited vulnerability. The post reiterated that CVE-2025-4008 enables root command execution and urged upgrading to version 6.2 or later.
CISA added the Smartbedded Meteobridge vulnerability to its Known Exploited Vulnerabilities catalog, signaling confirmed exploitation in the wild. The same update also added several other flaws from Samsung, Juniper ScreenOS, Jenkins, and GNU Bash.
The vendor advised users to upgrade to Meteobridge 6.2 or later to fix CVE-2025-4008, indicating a remediation was made available for affected devices. Versions before 6.2 remain vulnerable.
Smartbedded disclosed a high-severity command injection flaw in the Meteobridge management web interface, tracked as CVE-2025-4008. The vulnerability affects versions prior to 6.2 and can allow an unauthenticated adjacent attacker to execute arbitrary commands as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.