CVE-2025-32409
Last modified
CVE-2025-32409 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-32409?
How severe is CVE-2025-32409?
How do I fix CVE-2025-32409?
Are you affected by CVE-2025-32409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
