CVE-2025-27261: Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerability
Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27261?
The severity of CVE-2025-27261 is classified as critical due to its potential for unauthorized access to sensitive user and configuration data.
How do I fix CVE-2025-27261?
To fix CVE-2025-27261, update the Ericsson Indoor Connect 8855 to the latest version provided by Ericsson that addresses this SQL injection vulnerability.
What types of data are affected by CVE-2025-27261?
CVE-2025-27261 affects user data and configuration data in the Ericsson Indoor Connect 8855 system.
Can CVE-2025-27261 be exploited remotely?
Yes, CVE-2025-27261 can potentially be exploited remotely, allowing attackers to execute SQL injection attacks.
What actions should be taken after discovering CVE-2025-27261 on a device?
After discovering CVE-2025-27261, it is recommended to immediately patch the vulnerability and perform a security audit of affected devices.