CVE-2025-3364: HGiga PowerStation - Chroot Escape
Published Apr 8, 2025
·Updated
The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system.
Affected Software
1 affected component
Hgiga PowerStation
Remediation
Information
Update firmware to version x64.6.2.213 or later, then reboot PowerStation.
Event History
Apr 8, 2025
CVE Published
via MITRE·02:26 AM
Data Sourced
via MITRE·02:26 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Jun 20, 57255
Event
via FIRST·02:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-3364?
CVE-2025-3364 is classified as a critical severity vulnerability due to its potential to allow root access to the entire file system.
2
How do I fix CVE-2025-3364?
To mitigate CVE-2025-3364, apply security patches provided by HGiga for the PowerStation firmware.
3
Who is affected by CVE-2025-3364?
CVE-2025-3364 affects users of the HGiga PowerStation with SSH services enabled.
4
What type of vulnerability is CVE-2025-3364?
CVE-2025-3364 is a chroot escape vulnerability that allows attackers to bypass chroot restrictions.
5
Can CVE-2025-3364 be exploited remotely?
Yes, CVE-2025-3364 can potentially be exploited remotely if an attacker gains root privileges through SSH.