CVE-2025-9494 - CVE House
Back to Database
Status published High CVE-2025-9494

Viessmann Vitogate 300 OS Command Injection

Vulnerability Description

An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected installations. Specifically, the `/cgi-bin/vitogate.cgi` endpoint is affected, when the `form` JSON parameter is set to `form-0-2`. The vulnerability stems from the fact that that function at offset 0x21c24 does not properly sanitize supplied input before interpolating it into a format string which gets passed to `popen()`. Consequently, an authenticated attacker is able to inject arbitrary OS commands and thus gain code execution on affected devices.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9494

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • adhkr of LuwakLab working with Trend Micro Zero Day Initiative

Affected Vendor

Affected Software

Vitogate 300
Vulnerable Versions:
1

Timeline

Official Publish: September 23rd, 2025
Last Modified: September 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)