A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."
References
| Link | Resource |
|---|---|
| https://drive.google.com/file/d/1cZy-rfQXsF58kJIVs4UXj7usXJuhjZjA/view | Permissions Required |
| https://vuldb.com/?ctiid.320416 | Permissions Required VDB Entry |
| https://vuldb.com/?id.320416 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.626292 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2025-08-17 23:15
Updated : 2025-12-03 13:41
NVD link : CVE-2025-9094
Mitre link : CVE-2025-9094
CVE.ORG link : CVE-2025-9094
JSON object : View
Products Affected
thingsboard
- thingsboard
