Executive brief
Smartbedded Meteobridge is a device used to collect and manage data from weather stations. A critical security flaw allows an unauthorized person on the same local network to take complete control of the device. This could lead to the theft of weather data, disruption of monitoring services, or the device being used as a foothold to attack other systems on the network.
Technical details
A command injection vulnerability (CWE-77) exists in the web interface of Smartbedded Meteobridge, which is built using CGI shell scripts and C. The flaw is located in a specific web endpoint that fails to properly neutralize special elements, combined with a lack of authentication for critical functions (CWE-306). An unauthenticated attacker with adjacent network access can exploit this to execute arbitrary shell commands with root-level privileges. This vulnerability has been observed being exploited in the wild and is addressed in firmware version 6.2.
Affected products
- Smartbedded Meteobridge Firmware up to (excluding) 6.2
- Smartbedded Meteobridge VM up to (excluding) 6.2
Timeline
- 2025-05-21: disclosed: Initial disclosure by ONEKEY GmbH
- 2025-10-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-10-03: patched: NVD records indicate versions 6.2 and later are not affected