A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."
References
| Link | Resource |
|---|---|
| https://drive.google.com/file/d/1cZy-rfQXsF58kJIVs4UXj7usXJuhjZjA/view | Permissions Required |
| https://vuldb.com/?ctiid.320416 | Permissions Required VDB Entry |
| https://vuldb.com/?id.320416 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.626292 | Third Party Advisory VDB Entry |
Configurations
History
03 Dec 2025, 13:41
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:thingsboard:thingsboard:4.1:*:*:*:*:*:*:* | |
| First Time |
Thingsboard
Thingsboard thingsboard |
|
| References | () https://drive.google.com/file/d/1cZy-rfQXsF58kJIVs4UXj7usXJuhjZjA/view - Permissions Required | |
| References | () https://vuldb.com/?ctiid.320416 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.320416 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.626292 - Third Party Advisory, VDB Entry |
Information
Published : 2025-08-17 23:15
Updated : 2025-12-03 13:41
NVD link : CVE-2025-9094
Mitre link : CVE-2025-9094
CVE.ORG link : CVE-2025-9094
JSON object : View
Products Affected
thingsboard
- thingsboard
