Radiometer Products Remote Code Execution and Unauthorized Device Management Vulnerability

Vulnerability

A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management under specific internal conditions. Exploitation requires an established remote connection, with additional information obtained through other means. The issue stems from a weakness in the analyzer's application software. Affected customers have been informed about this vulnerability. This CVE is being published to provide transparency.

Impact

Successful exploitation allows for remote code execution and unauthorized management of the affected device.

Reproduction

The vulnerability can be reproduced by establishing a remote connection to the affected analyzer model with the application software version in use and the remote support feature enabled. Additional information, not specified in the context, is required to exploit the vulnerability.

Remediation

Customers should ensure their network is secure and follows best practices. Local Radiometer representatives will contact affected customers to discuss a permanent solution.

Added: Dec 17, 2025, 1:21 PM
Updated: Dec 17, 2025, 1:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
1.4
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.