CVE-2025-41451: Danfoss Ak-SM8XXA Series

High severity, CVSS 8.7. EPSS: 1% chance of exploitation in the next 30 days.

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.

Affected products

  • Danfoss Ak-SM8XXA Series: before 4.3.1 (fixed in 4.3.1)

Published 2025-08-22. Last modified 2026-06-17.