CVE-2025-4008 – Command Injection – Meteobridge VM & Firmware

ISGroup Cybersecurity

The Meteobridge web interface allows the system administrator to manage weather station data collection and administer their system through a web application written in shell scripts, CGI, and C. CVE-2025-4008 allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges (root) on vulnerable devices. With exploitation cases already confirmed and the vulnerability added to the CISA Known Exploited Vulnerabilities Catalog, it is critical to apply the available patches immediately.

Date2025-10-08 08:54:12
Information
  • Trending
  • Fix Available

Technical Summary

CVE-2025-4008 is a command injection flaw affecting Meteobridge VM & Firmware versions up to, but not including, version 6.2. The vulnerability is specifically located in the /public/template.cgi endpoint (also accessible via /public/template.cgi), a CGI shell script that improperly handles user input. The script parses user-controllable input from the $QUERY_STRING variable and uses it without sanitization in an eval call, allowing for arbitrary command-line command injection. Although authentication is enforced by uhttpd for directories such as cgi-bin, the vulnerable script is also accessible via the public directory, which is not protected, thus allowing for unauthenticated exploitation.

  • Basic exploit example: The vulnerability can be exploited by sending a GET request, passing malicious commands via the templatefile parameter, for example: /public/template.cgi?templatefile=$(command)

Recommendations

  1. Apply the patch immediately: Update Meteobridge to Version 6.2 (released May 13, 2025) or later.
  2. Isolate and disable remote access: Disable remote access to Meteobridge.
  3. Detection and monitoring activities: Perform audits to detect anomalies and analyze requests to the /cgi-bin/template.cgi endpoint.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert