Critical Vulnerability Information 1. Vulnerability Overview CVE ID: CVE-2025-8296 CVSS v3 Base Score: 8.8 CVSS v3 Vector String: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS v4 Base Score: 9.3 CVSS v4 Vector String: AV:A/AT:P/PR:N/UI:N/S:U/C:H/I:H/A:H/SC:S/SA:N/E:U/RL:O/RC:C/MAV:A/MAC:L/MPR:N/MUI:N/MS:U/MC:H/MI:H/MA:H 2. Affected Products Vendor: Güralp Systems Affected Products: Güralp FMUS Series Seismic Monitoring Devices (all versions) 3. Vulnerability Details Vulnerability Type: Missing Authentication for Critical Function (CWE-306) Description: The affected products provide an Internet-based command-line interface that allows unauthenticated users to modify hardware configurations, manipulate data, or reset the device. 4. Risk Assessment Successful exploitation of this vulnerability may allow attackers to: - Modify hardware configurations - Manipulate data - Factory reset the device 5. Background Information Critical Infrastructure Sector: Wholesale Manufacturing Deployment Countries/Regions: Worldwide Company Headquarters Location: United Kingdom 6. Researchers Reporter: Sonak Kondal of MicroSec (microsocial) reported this vulnerability to CISA 7. Mitigation Measures Users are advised to contact Güralp and keep systems updated Minimize network exposure Networks for local control systems and remote devices should be placed behind firewalls and isolated from business networks Use secure methods such as Virtual Private Networks (VPNs) for remote access 8. Update History July 31, 2025: Initial release