{ "schema_version": "1.4.0", "id": "GHSA-72r9-6vhw-cpmr", "modified": "2025-09-25T15:30:24Z", "published": "2025-09-25T15:30:24Z", "aliases": [ "CVE-2025-40836" ], "details": "Ericsson\nIndoor Connect 8855 contains an improper input validation vulnerability which if exploited can lead to loss of integrity and confidentiality, as well\nas unauthorized disclosure and modification of\n\n\n\nof user\nand configuration data. It may also be possible to execute commands with escalated privileges, impact\nservice availability, as well as modify system files and configuration\ndata.", "severity": [ { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40836" }, { "type": "WEB", "url": "https://www.ericsson.com/en/about-us/security/psirt/e2025-09-25" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-09-25T15:16:11Z" } }