CVE-2025-52548

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
References
Link Resource
https://www.armis.com/research/frostbyte10/ Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:copeland:e3_supervisory_controller_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:copeland:site_supervisor_bx_860-1240:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_bxe_860-1245:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_cx_860-1260:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_cxe_860-1265:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_rx_860-1220:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_rxe_860-1225:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_sf_860-1200:-:*:*:*:*:*:*:*

History

01 Oct 2025, 18:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
First Time Copeland site Supervisor Bxe 860-1245
Copeland site Supervisor Sf 860-1200
Copeland
Copeland site Supervisor Cxe 860-1265
Copeland site Supervisor Rx 860-1220
Copeland site Supervisor Cx 860-1260
Copeland site Supervisor Bx 860-1240
Copeland e3 Supervisory Controller Firmware
Copeland site Supervisor Rxe 860-1225
References () https://www.armis.com/research/frostbyte10/ - () https://www.armis.com/research/frostbyte10/ - Mitigation, Third Party Advisory
CPE cpe:2.3:h:copeland:site_supervisor_cx_860-1260:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_bxe_860-1245:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_rx_860-1220:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_sf_860-1200:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_rxe_860-1225:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_bx_860-1240:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_cxe_860-1265:-:*:*:*:*:*:*:*
cpe:2.3:o:copeland:e3_supervisory_controller_firmware:*:*:*:*:*:*:*:*

02 Sep 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-02 12:15

Updated : 2025-10-01 18:25


NVD link : CVE-2025-52548

Mitre link : CVE-2025-52548

CVE.ORG link : CVE-2025-52548


JSON object : View

Products Affected

copeland

  • site_supervisor_bx_860-1240
  • site_supervisor_bxe_860-1245
  • site_supervisor_rxe_860-1225
  • site_supervisor_cx_860-1260
  • e3_supervisory_controller_firmware
  • site_supervisor_cxe_860-1265
  • site_supervisor_sf_860-1200
  • site_supervisor_rx_860-1220
CWE
CWE-1242

Inclusion of Undocumented Features or Chicken Bits