CVE-2025-5113: Diviotec NBF232P

High severity, CVSS 8.6. EPSS: 8.2% chance of exploitation in the next 30 days.

The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.

Affected products

  • Diviotec NBF232P: up to and including 2.0170.3030
  • Diviotec NBF233P: up to and including 2.0170.3030
  • Diviotec NBR222P: up to and including 2.0170.3030
  • Diviotec NBR222PV: up to and including 2.0170.3030
  • Diviotec NBR224P: up to and including 2.0170.3030
  • Diviotec NBR225P: up to and including 2.0170.3030
  • Diviotec NBR226P: up to and including 2.0170.3030
  • Diviotec NDR252P: up to and including 2.0170.3030
  • Diviotec NDR255P: up to and including 2.0170.3030

Published 2025-06-02. Last modified 2026-06-17.