CISA-waarschuwing: Kritieke fout in Güralp FMUS-seismische apparaten (CVE-2025-8286)
juli 31, 2025 • César Daniel Barreto

CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1 9.8 (CVSS v4.0 9.3), the flaw is a textbook case of missing authentication for a critical function (CWE-306).
An open door over Telnet
The affected devices expose an unauthenticated Telnet-based command-line interface. Any attacker who can reach that open port over the network can connect without credentials and take privileged control — modifying hardware configuration, manipulating or corrupting the seismic data the instruments record, or triggering a full factory reset. Because the flaw is remotely exploitable with low complexity and requires no privileges or user interaction, it is trivial to abuse once the device is reachable.
Scope and vendor response
CISA lists all versions of the FMUS series as affected, and a later revision of the advisory expanded coverage to the Güralp MIN-series digitizers as well. The vulnerability was reported to CISA by Souvik Kandar of MicroSec. As of publication, Güralp had not confirmed an official firmware fix and did not respond to CISA’s coordination attempts, so operators cannot simply patch their way out.
How to reduce the risk
Seismic monitoring feeds early-warning and research systems, so data integrity matters as much as availability — a tampered device could inject false readings or go dark. CISA’s guidance is defensive and network-focused: ensure these devices are never reachable from the internet, place them behind firewalls and isolate them from business networks, and use up-to-date VPNs or jump hosts for any remote access. Operators should audit whether any FMUS or MIN unit is exposing Telnet and lock that access down immediately.

César Daniel Barreto
César Daniel Barreto is een gewaardeerd schrijver en expert op het gebied van cyberbeveiliging, die bekend staat om zijn diepgaande kennis en zijn vermogen om complexe onderwerpen op het gebied van cyberbeveiliging te vereenvoudigen. Met zijn uitgebreide ervaring in netwerk beveiliging en gegevensbescherming draagt hij regelmatig bij aan inzichtelijke artikelen en analyses over de nieuwste cyberbeveiligingstrends, waarmee hij zowel professionals als het publiek voorlicht.