CVE-2025-8480: (0Day) (Pwn2Own) Alpine iLX-507 Command Injection Remote Code Execution
Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the Tidal music streaming application. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26357.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-CAN-26357 - Compensating control
Because authentication is not required, restrict network access to Alpine iLX-507 devices hosting the Tidal music streaming application (e.g., via firewall/ACL so only trusted network segments can reach it).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8480?
CVE-2025-8480 is rated as critical due to its potential for remote code execution without authentication.
How do I fix CVE-2025-8480?
To fix CVE-2025-8480, it is recommended to apply the latest security updates provided by Alpine for the iLX-507 devices.
Who is affected by CVE-2025-8480?
CVE-2025-8480 affects all installations of Alpine iLX-507 devices that have not been patched.
What type of attack does CVE-2025-8480 enable?
CVE-2025-8480 enables network-adjacent attackers to execute arbitrary code on the affected devices.
Do I need authentication to exploit CVE-2025-8480?
No, CVE-2025-8480 can be exploited without any authentication.