CVE-2025-4008: Smartbedded Meteobridge Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-10-02. EPSS: 93.7% chance of exploitation in the next 30 days.

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

Affected products

  • Smartbedded Meteobridge Firmware: before 6.2 (fixed in 6.2)
  • Smartbedded Meteobridge Vm: before 6.2 (fixed in 6.2)

Published 2025-05-21. Last modified 2026-06-17.