CISA figyelmeztet a magas kockázatú sebezhetőségekre a DuraComm DP-10iN-100-MU-ban
július 23, 2025 • César Daniel Barreto

On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up to and including 4.10 are affected. The flaws were reported to CISA by Brandon Vincent of Arizona Public Service, and no public exploitation was known at the time of publication.
Three distinct weaknesses
CVE-2025-41425 (CVSS v3.1 7.1) is a cross-site scripting flaw that could be used to prevent legitimate users from reaching the web interface. CVE-2025-48733 (CVSS v3.1 7.5) is a missing-authentication issue: a function that should require authentication does not, letting an attacker repeatedly reboot the device and cause a denial of service. CVE-2025-53703 (CVSS v3.1 7.5) is a cleartext-transmission flaw — sensitive data is sent without encryption, so anyone able to observe the network traffic can intercept it.
Impact
All three are network-exploitable with low attack complexity; the missing-authentication and cleartext flaws require no privileges at all, while the XSS requires only low privileges. CISA’s overall assessment is that successful exploitation could allow an attacker to disclose sensitive information or cause a denial-of-service condition — knocking the panel offline through forced reboots or blocking access to its management interface.
Fix and mitigations
DuraComm has released a fix in version 4.10A, and operators should update to it. Beyond patching, CISA recommends the standard control-system hygiene: minimize network exposure so the panel is not reachable from the internet, place it behind a firewall, isolate it from business networks, and use secure, up-to-date remote access when needed.

César Dániel Barreto
César Daniel Barreto elismert kiberbiztonsági író és szakértő, aki mélyreható ismereteiről és képességéről ismert, hogy egyszerűsítse a bonyolult kiberbiztonsági témákat. Kiterjedt tapasztalattal rendelkezik a hálózatbiztonság és az adatvédelem terén, rendszeresen hozzájárul betekintő cikkekkel és elemzésekkel a legújabb kiberbiztonsági trendekről, oktatva mind a szakembereket, mind a nagyközönséget.