CVE-2025-52548
MEDIUMDescription
E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
Is your site exposed to CVE-2025-52548?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| copeland | e3_supervisory_controller_firmware |
| copeland | site_supervisor_bx_860-1240 |
| copeland | site_supervisor_bxe_860-1245 |
| copeland | site_supervisor_cx_860-1260 |
| copeland | site_supervisor_cxe_860-1265 |
| copeland | site_supervisor_rx_860-1220 |
| copeland | site_supervisor_rxe_860-1225 |
| copeland | site_supervisor_sf_860-1200 |
References
Other References
Frequently Asked Questions
What is CVE-2025-52548? +
How severe is CVE-2025-52548? +
What products are affected by CVE-2025-52548? +
How do I check if I'm vulnerable to CVE-2025-52548? +
Related Vulnerabilities
Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint …
DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative …
CWE-1242: Inclusion of Undocumented Features
Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: …
Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and …
Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall …