Indoor Connect 8855 Firmware
by Ericsson
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-40838 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information. | ||
| CVE-2025-40842 | 0.00 | — | 0.00 | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information. | |||
| CVE-2025-40841 | 0.00 | — | 0.00 | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information. | |||
| CVE-2025-27260 | 0.00 | — | 0.00 | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead to unauthorized modification of certain information | |||
| CVE-2025-40837 | 0.00 | — | 0.00 | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended. | |||
| CVE-2025-40836 | 0.00 | — | 0.00 | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges. | |||
| CVE-2025-27262 | 0.00 | — | 0.01 | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges. | |||
| CVE-2025-27261 | 0.00 | — | 0.00 | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data. |
- risk 0.49cvss 7.5epss 0.00
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.
- CVE-2025-40842Mar 25, 2026risk 0.00cvss —epss 0.00
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information.
- CVE-2025-40841Mar 25, 2026risk 0.00cvss —epss 0.00
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information.
- CVE-2025-27260Mar 25, 2026risk 0.00cvss —epss 0.00
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead to unauthorized modification of certain information
- CVE-2025-40837Sep 25, 2025risk 0.00cvss —epss 0.00
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.
- CVE-2025-40836Sep 25, 2025risk 0.00cvss —epss 0.00
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.
- CVE-2025-27262Sep 25, 2025risk 0.00cvss —epss 0.01
Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.
- CVE-2025-27261Sep 25, 2025risk 0.00cvss —epss 0.00
Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.