MEDIUM · 4.9

CVE-2025-52548

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker wi...

Vulnerability Description

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.

CVSS Score

4.9

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CopelandE3 Supervisory Controller Firmware< 2.31f01
CopelandSite Supervisor Bx 860-1240-
CopelandSite Supervisor Bxe 860-1245-
CopelandSite Supervisor Cx 860-1260-
CopelandSite Supervisor Cxe 860-1265-
CopelandSite Supervisor Rx 860-1220-
CopelandSite Supervisor Rxe 860-1225-
CopelandSite Supervisor Sf 860-1200-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-52548?

CVE-2025-52548 is a vulnerability with a CVSS score of 4.9 (MEDIUM). E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker wi...

How severe is CVE-2025-52548?

CVE-2025-52548 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-52548?

Check the references section above for vendor advisories and patch information. Affected products include: Copeland E3 Supervisory Controller Firmware, Copeland Site Supervisor Bx 860-1240, Copeland Site Supervisor Bxe 860-1245, Copeland Site Supervisor Cx 860-1260, Copeland Site Supervisor Cxe 860-1265.