File overwrite via hard-coded NFS update host
Published Feb 25, 2025 · Updated Feb 25, 2025
Hidden functionality in Contec Medical Systems CMS8000 Patient Monitor version 0 allows attackers to overwrite files via an impersonated NFS server. The firmware's update binary bypasses configured network settings, mounts 202.114.4.119:/pm, and recursively copies its contents over /opt/bin without integrity validation. Exploitation requires control or impersonation of the routable host plus a precisely timed physical C-button press during boot; replaced executables run with root privileges.
Summary
What happened
Hidden functionality in Contec Medical Systems CMS8000 Patient Monitor version 0 allows attackers to overwrite files via an impersonated NFS server. The firmware's update binary bypasses configured network settings, mounts 202.114.4.119:/pm, and recursively copies its contents over /opt/bin without integrity validation. Exploitation requires control or impersonation of the routable host plus a precisely timed physical C-button press during boot; replaced executables run with root privileges.
The record
- CVE
- CVE-2025-1204
- Published
- Feb 25, 2025
- Updated
- Feb 25, 2025
- Vendor
- Contec Medical Systems Co., Ltd.
- Product
- CMS8000 Patient Monitor
- Classifications
- CWE-912, T1105, T1557
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Feb 25, 2025CVE publishedPublication date reported by the CVE source.
- Feb 25, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Team82 CMS8000 firmware-update proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo