CVE-2020-25197: Ge RT430 Firmware

High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.

A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.

Affected products

  • Ge RT430 Firmware: before 08a06 (fixed in 08a06)
  • Ge RT431 Firmware: before 08a06 (fixed in 08a06)
  • Ge RT434 Firmware: before 08a06 (fixed in 08a06)

Published 2022-03-18. Last modified 2026-06-17.