CVE-2025-27262: Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerability
Published Sep 25, 2025
·Updated
Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.
Affected Software
3 affected components
Ericsson Indoor Connect 8855
All of the following
Ericsson Indoor Connect 8855 Firmware<2025.q2
Ericsson Indoor Connect 8855
Event History
Sep 25, 2025
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27262?
CVE-2025-27262 is considered a high severity vulnerability due to its potential impact on integrity, confidentiality, and unauthorized data access.
2
How do I fix CVE-2025-27262?
To fix CVE-2025-27262, apply the latest security patches provided by Ericsson for the Indoor Connect 8855 product.
3
Who is affected by CVE-2025-27262?
CVE-2025-27262 affects users of the Ericsson Indoor Connect 8855 device.
4
What type of vulnerability is CVE-2025-27262?
CVE-2025-27262 is a command injection vulnerability that allows for unauthorized command execution.
5
What are the potential consequences of exploiting CVE-2025-27262?
Exploiting CVE-2025-27262 can lead to loss of integrity and confidentiality, along with unauthorized disclosure and modification of user and configuration data.