CVE-2025-32409 - CVE House
Back to Database
Status published High CVE-2025-32409

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote...

Vulnerability Description

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32409

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SuperNote A6 X2 Nomad
Vulnerable Versions:
0

Timeline

Official Publish: April 7th, 2025
Last Modified: April 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)