CVE-2025-60938: Openenergymonitor Emoncms

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset within the /admin/upload-custom-firmware endpoint.

Affected products

Published 2025-10-24. Last modified 2026-06-17.