Two high-severity vulnerabilities (CVE-2025-9494 and CVE-2025-9495) have been identified in Viessmann Vitogate 300 devices prior to version 3.1.0.1. Exploitation could allow attackers to inject OS commands or bypass security controls, potentially impacting critical infrastructure. No public exploitation has been reported, and users are strongly advised to update to version 3.1.0.1 or newer and follow CISA's recommended defensive measures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-9494 was publicly listed as a high-severity OS command injection vulnerability in the Viessmann Vitogate 300, with a CVSS 4.0 score of 8.5. Publicly available details identified the affected product, vulnerability class, and severity.
CISA published ICS advisory ICSA-25-266-04 covering a security issue affecting the Viessmann Vitogate 300. The advisory marks the public disclosure of the vulnerability to defenders and asset owners.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.