cbcvebase.

Ericsson Indoor Connect 8855 vulnerabilities

8 known vulnerabilities affecting ericsson/indoor_connect_8855.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-40836P2CRITICALCVSS 9.8fixed in 2025.Q22025-09-25
CVE-2025-40836 [CRITICAL] CWE-20 CVE-2025-40836: Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.
nvd
CVE-2025-27261P3CRITICALCVSS 9.8fixed in 2025.Q22025-09-25
CVE-2025-27261 [CRITICAL] CWE-89 CVE-2025-27261: Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result i Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.
nvd
CVE-2025-40837P3HIGHCVSS 8.8fixed in 2025.Q22025-09-25
CVE-2025-40837 [HIGH] CWE-862 CVE-2025-40837: Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can a Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.
nvd
CVE-2025-27262P3HIGHCVSS 7.8fixed in 2025.Q22025-09-25
CVE-2025-27262 [HIGH] CWE-78 CVE-2025-27262: Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can resul Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.
nvd
CVE-2025-40838P3HIGHCVSS 7.5fixed in 2025.Q22025-09-25
CVE-2025-40838 [HIGH] CWE-522 CVE-2025-40838: Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.
nvd
CVE-2025-27260P3HIGHCVSS 7.5fixed in 2025.Q32026-03-25
CVE-2025-27260 [HIGH] CWE-790 CVE-2025-27260: Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Ele Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead to unauthorized modification of certain information
nvd
CVE-2025-40842P4MEDIUMCVSS 6.1fixed in 2025.Q32026-03-25
CVE-2025-40842 [MEDIUM] CWE-79 CVE-2025-40842: Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnera Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information.
nvd
CVE-2025-40841P4MEDIUMCVSS 4.3fixed in 2025.Q32026-03-25
CVE-2025-40841 [MEDIUM] CWE-352 CVE-2025-40841: Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information.
nvd
Ericsson Indoor Connect 8855 vulnerabilities | cvebase