CVE-2025-7937: Supermicro BMC firmware update validation bypass
Published Sep 19, 2025
·Updated
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.
Affected Software
1 affected component
Supermicro MBD-X12STW
Event History
Sep 19, 2025
CVE Published
via MITRE·02:09 AM
Data Sourced
via MITRE·02:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Sep 24, 2025
News Published
via BleepingComputer·08:13 PM
News Published
via BleepingComputer·08:15 PM
Feb 4, 57704
Event
via NVD·05:46 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-7937?
CVE-2025-7937 is classified as a high-severity vulnerability due to its potential for allowing unauthorized firmware updates.
2
How do I fix CVE-2025-7937?
To fix CVE-2025-7937, update the Supermicro BMC firmware to the latest version provided by Supermicro.
3
What attack vector is associated with CVE-2025-7937?
CVE-2025-7937 allows attackers to exploit the firmware validation logic in Supermicro BMC, making it possible to upload malicious firmware.
4
Which products are affected by CVE-2025-7937?
CVE-2025-7937 specifically affects the Supermicro MBD-X12STW motherboard.
5
What can be done to mitigate CVE-2025-7937 before a patch is available?
To mitigate CVE-2025-7937, restrict access to the BMC interface and monitor firmware updates closely.