CVE-2025-8473: (0Day) (Pwn2Own) Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability
Alpine iLX-507 UPDMwstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the UPDMwstpCBCUpdStart function. The issue results from the lack of proper validation of user-supplied data before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26317.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate physically present attacks by restricting access to Alpine iLX-507 device interfaces/network paths that reach the UPDM_wstpCBCUpdStart functionality (e.g., via network segmentation/ACL/firewall rules).
- Compensating control
Apply mitigations specifically associated with ZDI-CAN-26317 for Alpine iLX-507, addressing the UPDM_wstpCBCUpdStart command injection (root context) caused by improper validation of user-supplied data before system call execution.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8473?
The CVE-2025-8473 vulnerability is classified as critical due to its potential to allow arbitrary code execution on affected devices.
How do I fix CVE-2025-8473?
To fix CVE-2025-8473, ensure you update the firmware of the Alpine iLX-507 device to the latest available version that addresses this vulnerability.
Who can exploit CVE-2025-8473?
CVE-2025-8473 can be exploited by physically present attackers without the need for authentication.
What devices are affected by CVE-2025-8473?
CVE-2025-8473 specifically affects the Alpine iLX-507 devices.
What type of vulnerability is CVE-2025-8473?
CVE-2025-8473 is a command injection vulnerability that allows attackers to execute arbitrary commands.