CVE-2025-41451: Post-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA Series
Published Aug 22, 2025
·Updated
Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.
Affected Software
1 affected component
Danfoss AK-SM8xxA Series<4.3.1
Event History
Aug 22, 2025
CVE Published
via MITRE·02:40 AM
Data Sourced
via MITRE·02:40 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41451?
CVE-2025-41451 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2025-41451?
To fix CVE-2025-41451, upgrade the Danfoss AK-SM8xxA Series to version 4.3.1 or later.
3
What software versions are affected by CVE-2025-41451?
CVE-2025-41451 affects Danfoss AK-SM8xxA Series versions prior to 4.3.1.
4
What type of vulnerability is CVE-2025-41451?
CVE-2025-41451 is an OS shell command injection vulnerability.
5
What are the potential impacts of CVE-2025-41451?
The potential impacts of CVE-2025-41451 include unauthorized post-authenticated remote code execution.