The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C.This web interface exposes an endpoint that is vulnerable to command injection.Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
id: CVE-2025-4008
info:
name: MeteoBridge <= 6.1 - Remote Code Execution
author: iamnoooob,pdre
...