Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.
History

Tue, 08 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Apr 2025 21:45:00 +0000

Type Values Removed Values Added
Description Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-08T15:58:04.589Z

Reserved: 2025-04-07T00:00:00.000Z

Link: CVE-2025-32409

cve-icon Vulnrichment

Updated: 2025-04-08T14:20:58.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-07T22:15:16.963

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-32409

cve-icon Redhat

No data.