HIGH
OS command injection in MiR robots and MiR fleet via crafted HTTP requests
Published Aug 8, 2025
8.8
HIGHCVSS 3.1
EPSS 1.33%
Description
MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP request crafted by an authenticated user could allow the execution of arbitrary commands on the underlying operating system.
Affected products
-
Affected
- ≥ 0, < 3.0.0
-
Affected
- ≥ 0, < 3.0.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mobile Industrial Robots | MiR Fleet | unaffected | Affected
|
| Mobile Industrial Robots | MiR Robots | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to the newest software version, at least version 3.0.0
Weaknesses (1)
References (3)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TRO
Published Aug 8, 2025
Updated Nov 5, 2025
Reserved Aug 8, 2025
Link CVE-2025-8748
CISA Vulnrichment
Updated Aug 8, 2025
Red Hat
No data
GitHub
No data