CVE-2025-2605: Authenticated command injection
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2605?
CVE-2025-2605 has a high severity rating due to the potential for privilege abuse through OS command injection.
How do I fix CVE-2025-2605?
To fix CVE-2025-2605, update Honeywell MB-Secure to version 12.53 or later, and MB-Secure PRO to version 03.09 or later.
Which products are affected by CVE-2025-2605?
CVE-2025-2605 affects Honeywell MB-Secure versions from 11.04 to before 12.53 and MB-Secure PRO versions from 01.06 to before 03.09.
What type of vulnerability is CVE-2025-2605?
CVE-2025-2605 is classified as an OS command injection vulnerability due to improper neutralization of special elements.
What are the potential consequences of CVE-2025-2605?
The consequences of CVE-2025-2605 can include unauthorized privilege escalation and possible control over affected systems.