Back

MEDIUM

Injection vulnerability in Iridium Certus 700

Published May 23, 2025

Description

The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system will use the JSON ID and therefore fail. This can be exploited by an attacker to create rules that cannot be deleted unless the device is reset to factory defaults.

Affected products

Remediation

Vendor solution

The vulnerability has been resolved by the Intellian Technologies team in the Q2 2025 release.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published May 23, 2025
Updated May 23, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated May 23, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a