การแจ้งเตือนจาก CISA: ข้อบกพร่องสำคัญในอุปกรณ์แผ่นดินไหว Güralp FMUS (CVE-2025-8286)

กรกฎาคม 31, 2025 • César Daniel Barreto

Güralp Systems Güralp FMUS series cybersecurity vulnerability alert CVSS 9.3

CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1 9.8 (CVSS v4.0 9.3), the flaw is a textbook case of missing authentication for a critical function (CWE-306).

An open door over Telnet

The affected devices expose an unauthenticated Telnet-based command-line interface. Any attacker who can reach that open port over the network can connect without credentials and take privileged control — modifying hardware configuration, manipulating or corrupting the seismic data the instruments record, or triggering a full factory reset. Because the flaw is remotely exploitable with low complexity and requires no privileges or user interaction, it is trivial to abuse once the device is reachable.

Scope and vendor response

CISA lists all versions of the FMUS series as affected, and a later revision of the advisory expanded coverage to the Güralp MIN-series digitizers as well. The vulnerability was reported to CISA by Souvik Kandar of MicroSec. As of publication, Güralp had not confirmed an official firmware fix and did not respond to CISA’s coordination attempts, so operators cannot simply patch their way out.

How to reduce the risk

Seismic monitoring feeds early-warning and research systems, so data integrity matters as much as availability — a tampered device could inject false readings or go dark. CISA’s guidance is defensive and network-focused: ensure these devices are never reachable from the internet, place them behind firewalls and isolate them from business networks, and use up-to-date VPNs or jump hosts for any remote access. Operators should audit whether any FMUS or MIN unit is exposing Telnet and lock that access down immediately.

ซีซาร์ ดาเนียล บาร์เรโต, ผู้เขียนด้านความปลอดภัยทางไซเบอร์ที่ Security Briefing

เซซาร์ ดาเนียล บาร์เรโต

César Daniel Barreto เป็นนักเขียนและผู้เชี่ยวชาญด้านความปลอดภัยทางไซเบอร์ที่มีชื่อเสียง ซึ่งเป็นที่รู้จักจากความรู้เชิงลึกและความสามารถในการทำให้หัวข้อความปลอดภัยทางไซเบอร์ที่ซับซ้อนนั้นง่ายขึ้น ด้วยประสบการณ์อันยาวนานด้านความปลอดภัยเครือข่ายและการปกป้องข้อมูล เขามักจะเขียนบทความเชิงลึกและการวิเคราะห์เกี่ยวกับแนวโน้มด้านความปลอดภัยทางไซเบอร์ล่าสุดเพื่อให้ความรู้แก่ทั้งผู้เชี่ยวชาญและสาธารณชน

  1. ฉลองครบรอบ 10 ปีของ Cyber Essentials: ทศวรรษแห่งการเสริมสร้างการป้องกันทางไซเบอร์สำหรับธุรกิจ
  2. วิธีที่บล็อกเชนและคริปโตทำให้การเล่นเกมปลอดภัยยิ่งขึ้น
  3. GTA Group เผยแพร่ผลการวิจัยเกี่ยวกับมัลแวร์ Hermit
  4. แนวทางการใช้กระเป๋าเงินอย่างปลอดภัยสำหรับการลงทุนโทเค็นใหม่: การปกป้องสินทรัพย์ดิจิทัลของคุณ
  5. ปัญหา TikTok: การสร้างสมดุลระหว่างความบันเทิง 
  6. การหลอกลวงทางคริปโต
  7. วิธีปกป้องโครงสร้างพื้นฐานที่สำคัญจากการโจมตีห่วงโซ่อุปทานในระหว่างการทำงาน
  8. เกมคลาสสิกถูกใช้ในแคมเปญมัลแวร์อย่างไร
  9. การสำรวจมัลแวร์ที่ได้รับการสนับสนุนจากรัฐอย่างละเอียด
  10. USPhoneBook และความเสี่ยงด้านความเป็นส่วนตัว: วิธีการเรียกคืนข้อมูลส่วนบุคคลของคุณ
  11. วิธีสังเกตการหลอกลวงคริปโตก่อนที่มันจะทำให้กระเป๋าเงินของคุณหมดตัว
  12. เทคโนโลยีบล็อกเชนช่วยให้การทำธุรกรรมดิจิทัลเร็วขึ้นและปลอดภัยขึ้นได้อย่างไร

Login

Already have an account? Sign in to pick up where you left off.

Register

New here? Create an account to follow our latest security briefings.

thThai