Junglewise Threat Intelligence

CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerability

CVE-2025-1976 · Severity: critical · CVSS 6.7 · Exploited in the wild · Published 2025-04-28

Vendors: Broadcom.

Executive brief

Broadcom Brocade Fabric OS contains a code injection vulnerability (CWE-94/CWE-78) that allows a local user with administrative privileges to execute arbitrary code with full root privileges. This vulnerability affects versions 9.1.0 through 9.1.1d6, where root access was intended to be restricted.

Affected products

  • Broadcom Fabric OS 9.1.0 through 9.1.1d6

Timeline

  • 2025-04-23: disclosed: Initial CVE entry received from Brocade Communications Systems, LLC
  • 2025-04-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-04-28: exploited: Reported as exploited in the wild per CISA KEV entry