CVE-2025-52548
E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
Published:Sep 2, 2025
Last Modified:Oct 1, 2025
EPS:Sep 2, 2025
EPSS Score:0.00047
CVSS Score:4.9
Affected Products
Vendor
Product
Action
Vendor
Copeland
Product
E3 Supervisory Controller Firmware
Copeland
E3 Supervisory Controller Firmware
Vendor
Copeland
Product
Site Supervisor Bx 860-1240
Copeland
Site Supervisor Bx 860-1240
Vendor
Copeland
Product
Site Supervisor Bxe 860-1245
Copeland
Site Supervisor Bxe 860-1245
Vendor
Copeland
Product
Site Supervisor Cx 860-1260
Copeland
Site Supervisor Cx 860-1260
Vendor
Copeland
Product
Site Supervisor Cxe 860-1265
Copeland
Site Supervisor Cxe 860-1265
Vendor
Copeland
Product
Site Supervisor Rx 860-1220
Copeland
Site Supervisor Rx 860-1220
Vendor
Copeland
Product
Site Supervisor Rxe 860-1225
Copeland
Site Supervisor Rxe 860-1225
Vendor
Copeland
Product
Site Supervisor Sf 860-1200
Copeland
Site Supervisor Sf 860-1200
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
