Junglewise Threat Intelligence

CVE-2025-7024: Airbus TETRA Connectivity Server privilege escalation via incorrect permissions

CVE-2025-7024 · Severity: high · CVSS 7.3 · Published 2026-04-03

Executive brief

A vulnerability in the Airbus TETRA Connectivity Server, a system used for critical radio communications, could allow an attacker to gain full control over the server. By exploiting incorrect folder permissions, an attacker can trick a user into placing a malicious file that grants the attacker administrative (SYSTEM) privileges. This could lead to a complete service outage or unauthorized access to sensitive communication data.

Technical details

The vulnerability is classified as CWE-276 (Incorrect Default Permissions) within the Airbus PSS TETRA Connectivity Server version 7.0 running on Windows Server OS. The application installs directories with insecure access control lists (ACLs), allowing low-privileged users to write files into sensitive locations. An attacker can achieve arbitrary code execution with SYSTEM privileges by utilizing a social engineering component (user interaction) to place a malicious file in the affected directory. A fix has been developed and distributed to impacted customers.

Affected products

  • Airbus TETRA Connectivity Server 7.0

Timeline

  • 2026-04-03: advisory: Initial disclosure by Airbus
  • 2026-04-03: patched: Fix made available to customers

References