CVE-2025-0680

CRITICAL

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.

Affects 0 products across 1 vendor.

BCS7.37
CVSS 3.19.8
CVSS v49.3
EPSS0.6%
Percentile46th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the device cloud RPC command handling process allows remote attackers to take control of arbitrary devices connected to the cloud.

BSID: BS-2025-GLOBAL-210618-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-0680?
A critical vulnerability in the device cloud RPC command handling process allows remote attackers to take control of arbitrary devices connected to the cloud.
What is the CVSS score for CVE-2025-0680?
CVE-2025-0680 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2025-0680 actively exploited?
No confirmed active exploitation of CVE-2025-0680 as of 2026-05-30.
How do I remediate CVE-2025-0680?
Priority: IMMEDIATE. Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-25-030-02
What systems are affected by CVE-2025-0680?
CVE-2025-0680 affects: Cloud.
Vulnerability Details
CVE IDCVE-2025-0680
BSIDBS-2025-GLOBAL-210618-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-01-30
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the way the device cloud handles RPC commands, enabling an attacker to send malicious commands that can compromise the device's control.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cloud —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 566 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash21e2a3d7b3085a34471926e78a10440f591d0d632365f4b3d6317b3097a5aa5c9b28e417227b192449012fb77267621b1bcc7c60e884180dd9ecc9c484200898
Related CVEs affecting Cloud
CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2025-54122 10.0 Manager-io/Manager is accounting software. A critical unauthenticated full re... CVE-2025-64180 10.0 Manager-io/Manager is accounting software. In Manager Desktop and Server vers... CVE-2026-0501 9.9 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Prem... CVE-2025-47282 9.9 Gardener External DNS Management is an environment to manage external DNS ent...
View all Cloud CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →