CVE-2025-32409
Last modified
CVE-2025-32409 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-32409?
How severe is CVE-2025-32409?
How do I fix CVE-2025-32409?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-32403An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or ear…9.8
- CVE-2025-32404An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or ear…9.8
- CVE-2025-32405An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or ear…7.5
- CVE-2025-32406An XXE issue in the Director NBR component in NAKIVO Backup …8.6
- CVE-2025-32407Samsung Internet for Galaxy Watch version 5.0.9, available u…5.9
- CVE-2025-32408In Soffid Console 3.6.31 before 3.6.32, authorization to use…2.5
- CVE-2025-3241A vulnerability, which was classified as problematic, was fo…9.8
- CVE-2025-32412Fuji Electric Smart Editor is vulnerable to an out-of-bounds…8.4
- CVE-2025-32413Vulnerability-Lookup before 2.7.1 allows stored XSS via a us…6.4
- CVE-2025-32414In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bo…7.5
- CVE-2025-32415In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchema…7.5
- CVE-2025-3242A vulnerability has been found in PHPGurukul e-Diary Managem…9.8
Are you affected by CVE-2025-32409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
