CVE-2025-32409
CVE-2025-32409
Título es
CVE-2025-32409
Lun, 07/04/2025 – 22:15
Tipo
CWE-23
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-32409
Descripción en
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.
08/04/2025
08/04/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
8.10
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
Enviar en el boletín
Off