تنبيه CISA: ثغرة خطيرة في أجهزة Güralp FMUS الزلزالية (CVE-2025-8286)

يوليو 31, 2025 • César Daniel Barreto

Güralp Systems Güralp FMUS series cybersecurity vulnerability alert CVSS 9.3

CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1 9.8 (CVSS v4.0 9.3), the flaw is a textbook case of missing authentication for a critical function (CWE-306).

An open door over Telnet

The affected devices expose an unauthenticated Telnet-based command-line interface. Any attacker who can reach that open port over the network can connect without credentials and take privileged control — modifying hardware configuration, manipulating or corrupting the seismic data the instruments record, or triggering a full factory reset. Because the flaw is remotely exploitable with low complexity and requires no privileges or user interaction, it is trivial to abuse once the device is reachable.

Scope and vendor response

CISA lists all versions of the FMUS series as affected, and a later revision of the advisory expanded coverage to the Güralp MIN-series digitizers as well. The vulnerability was reported to CISA by Souvik Kandar of MicroSec. As of publication, Güralp had not confirmed an official firmware fix and did not respond to CISA’s coordination attempts, so operators cannot simply patch their way out.

How to reduce the risk

Seismic monitoring feeds early-warning and research systems, so data integrity matters as much as availability — a tampered device could inject false readings or go dark. CISA’s guidance is defensive and network-focused: ensure these devices are never reachable from the internet, place them behind firewalls and isolate them from business networks, and use up-to-date VPNs or jump hosts for any remote access. Operators should audit whether any FMUS or MIN unit is exposing Telnet and lock that access down immediately.

César Daniel Barreto, Cybersecurity Author at Security Briefing

سيزار دانييل باريتو

سيزار دانييل باريتو كاتب وخبير مرموق في مجال الأمن السيبراني، معروف بمعرفته العميقة وقدرته على تبسيط مواضيع الأمن السيبراني المعقدة. وبفضل خبرته الواسعة في مجال أمن الشبكات وحماية البيانات، يساهم بانتظام بمقالات وتحليلات ثاقبة حول أحدث اتجاهات الأمن السيبراني، لتثقيف كل من المحترفين والجمهور.

arArabic