VYPR
Medium severity4.9NVD Advisory· Published Sep 2, 2025· Updated Jun 17, 2026

CVE-2025-52548

CVE-2025-52548

Description

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.