Back to Database
Status published
Critical
CVE-2023-25911
Authenticated OS Command Injection in Danfoss AK-EM100
Vulnerability Description
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25911
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Jony Schats (Hackdefense)
- Stan Plasmeijer (Hackdefense)
- Max van der Horst (DIVD)
More from Danfoss
View All →CVE-2025-41452
Post auth nginx configuration injection in Danfoss AK-SM8xxA Series
Medium
6.8
CVE-2025-41451
Post-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA Series
High
8.7
CVE-2025-41450
Authentication bypass with privileged access in Danfoss AK-SM 8xxA Series prior to version 4.2
High
8.2
CVE-2023-25915
Authenticated Remote Command Execution in Danfoss AK-SM800A
Critical
9.9
CVE-2023-25914
Authneticated Path Traversal in Danfoss AK-SM800A
High
8.8
Affected Vendor
Danfoss
View all reports →Affected Software
AK-EM100
Vulnerable Versions:
< 2.2.0.12
Timeline
Official Publish:
June 11th, 2023
Last Modified:
January 9th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H