CVE-2025-40837: Ericsson Indoor Connect 8855 - Missing Authorization Vulnerability
Published Sep 25, 2025
·Updated
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.
Affected Software
3 affected components
Ericsson Indoor Connect 8855
All of the following
Ericsson Indoor Connect 8855 Firmware<2025.q2
Ericsson Indoor Connect 8855
Event History
Sep 25, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40837?
CVE-2025-40837 is classified as a high severity vulnerability due to the potential for unauthorized access to higher privileges.
2
How do I fix CVE-2025-40837?
To fix CVE-2025-40837, ensure that you update your Ericsson Indoor Connect 8855 to the latest patched version from the vendor.
3
What does CVE-2025-40837 affect?
CVE-2025-40837 specifically affects the Ericsson Indoor Connect 8855 product.
4
What type of vulnerability is CVE-2025-40837?
CVE-2025-40837 is a missing authorization vulnerability that can be exploited to elevate user privileges.
5
Can CVE-2025-40837 be exploited remotely?
Yes, CVE-2025-40837 can potentially be exploited remotely due to the nature of the missing authorization.