CVE-2024-25002: Bosch Network Synchronizer

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.

Affected products

  • Bosch Network Synchronizer: before 9.30 (fixed in 9.30)
  • Bosch Network Synchronizer Enterprise: before 9.30 (fixed in 9.30)
  • Bosch Network Synchronizer Standard: before 9.30 (fixed in 9.30)

Published 2024-03-25. Last modified 2026-06-17.