CVE-2025-41451

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Seriesprior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
DanfossCNA
---
---
CISA-ADPADP
---
---