CVE detail
CVE-2020-25197 — CVE-2020-25197
Published 2022-03-18 · Modified 2026-06-17 · Vendor ge · Product rt430_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0317
EPSS probability
exploitation probability, 30d
87.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References