CVE-2020-25150: Bbraun Datamodule Compactplus

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.

Affected products

  • Bbraun Datamodule Compactplus: version a10 only; version a11 only
  • Bbraun Spacecom: up to and including l81

Published 2022-04-14. Last modified 2026-06-17.