Description

Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged network access for the configuration utility can execute arbitrary commands on the underlying OS to obtain root SSH access to the TropOS 4th Gen device.

INFO

Published Date :

2025-10-28T12:15:29.573Z

Last Modified :

2025-10-28T13:14:18.210Z

Source :

Hitachi Energy
AFFECTED PRODUCTS

The following products are affected by CVE-2025-1036 vulnerability.

Vendors Products
Hitachienergy
  • Tropos
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-1036.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability