Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.
                
            References
                    Configurations
                    No configuration.
History
                    22 Apr 2025, 15:16
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
| CWE | CWE-494 | |
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28236 - | 
18 Apr 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-18 18:15
Updated : 2025-04-22 15:16
NVD link : CVE-2025-28236
Mitre link : CVE-2025-28236
CVE.ORG link : CVE-2025-28236
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-494
                        
            Download of Code Without Integrity Check
