CVE-2025-5113: Diviotec NBF232P
High severity, CVSS 8.6. EPSS: 8.2% chance of exploitation in the next 30 days.
The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.
Affected products
- Diviotec NBF232P: up to and including 2.0170.3030
- Diviotec NBF233P: up to and including 2.0170.3030
- Diviotec NBR222P: up to and including 2.0170.3030
- Diviotec NBR222PV: up to and including 2.0170.3030
- Diviotec NBR224P: up to and including 2.0170.3030
- Diviotec NBR225P: up to and including 2.0170.3030
- Diviotec NBR226P: up to and including 2.0170.3030
- Diviotec NDR252P: up to and including 2.0170.3030
- Diviotec NDR255P: up to and including 2.0170.3030
Published 2025-06-02. Last modified 2026-06-17.