Back to Database
Status published
Critical
CVE-2023-25915
Authenticated Remote Command Execution in Danfoss AK-SM800A
Vulnerability Description
Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25915
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Synacktiv
- Max van der Horst (DIVD)
More from Danfoss
View All →CVE-2025-41452
Post auth nginx configuration injection in Danfoss AK-SM8xxA Series
Medium
6.8
CVE-2025-41451
Post-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA Series
High
8.7
CVE-2025-41450
Authentication bypass with privileged access in Danfoss AK-SM 8xxA Series prior to version 4.2
High
8.2
CVE-2023-25914
Authneticated Path Traversal in Danfoss AK-SM800A
High
8.8
CVE-2023-25913
Authentication Bypass in Danfoss AK-SM800A
High
7.5
Affected Vendor
Danfoss
View all reports →Affected Software
AK-SM800A
Vulnerable Versions:
< 3.3
Timeline
Official Publish:
August 21st, 2023
Last Modified:
January 9th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H