id: CVE-2025-8286 info: name: Güralp Systems FMUS Series - Unauthenticated Access severity: critical author: darses description: | Güralp Systems FMUS Series Seismic Monitoring Devices expose an unauthenticated Telnet-based command line interface that allows attackers to modify hardware configurations, manipulate data, or factory reset the device. impact: | Successful exploitation of this vulnerability could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device. reference: - https://www.cisa.gov/news-events/ics-advisories/icsa-25-212-01 - https://www.cve.org/CVERecord?id=CVE-2025-8286 remediation: | Update to the latest firmware version or apply vendor recommended patches to secure Telnet access. classification: cwe-id: CWE-306 cve-id: CVE-2025-8286 epss-score: 0.01217 epss-percentile: 0.65434 cvss-metrics: "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cvss-score: 9.8 metadata: verified: true vendor: guralp_systems product: fmus_series_seismic_monitoring_devices shodan-query: '"Welcome to " "list of available commands" port:4244' fofa-query: '"Welcome to " && "list of available commands" && port="4244"' tags: cve,cve2025,tcp,network,telnet,guralp,ics,vuln tcp: - host: - "{{Hostname}}" port: 4244 inputs: - data: "\n" read: 256 name: banner - data: "system info\n" read: 256 name: system_info matchers-condition: and matchers: - type: word part: banner words: - "Welcome to " - 'type "help" for a list of available commands' condition: and - type: word part: system_info words: - "Host Name: " - "Firmware Version: " condition: and extractors: - type: regex part: system_info group: 1 regex: - "Host\\s+Name:\\s+([\\w\\d\\.\\-]+)" - type: regex part: system_info group: 1 regex: - "Firmware\\s+Version:\\s+([\\d\\.\\-]+)" # digest: 4b0a004830460221009bb2a5d33528e9922ed658ea82953b5f08b4cd897bce535d9063e67060e6877e022100f10b543ae472a46371e8e29911ee99cc35bb8b3d0c79242ade0bfd0cf72b7c64:922c64590222798bb761d5b6d8e72950