CRITICAL🇵🇱 Wersja polska

CVE-2025-64120

CVSS 9.4v4.0pub. 2026-01-02upd. 2026-02-26

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): from 2.3.8 before 2.5.1.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters passed to operating system commands (CWE-78). The device management application does not properly filter user-supplied input data, which allows embedding additional shell commands. An attacker with basic privileges (PR:L) can send a specially crafted network request and cause the system to execute the provided commands with the privileges of the application process.

Impact

Successful exploitation of the vulnerability may allow an attacker to gain full control over the device, steal configuration and operational data, disrupt energy storage installation operations, and potentially affect systems connected to the MSC controller.

Mitigation & patch

Update Multi-Stack Controller (MSC) software to version 2.5.1 or later. If immediate update is not possible, it is recommended to isolate MSC devices from public networks and restrict access only to trusted hosts using firewall or VLAN networks. Detailed information is available in the manufacturer's advisory at the address indicated in the references.

Who is affected

Nuvation Energy Multi-Stack Controller (MSC) in versions from 2.3.8 to 2.5.1 (exclusive), supported by the nPlatform on devices: NuvMSC3-04S-C, NuvMSC3-08S-C, NuvMSC3-12S-C, NuvMSC3-16S-C.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:X/RE:X/U:X
  • Nuvationenergy Nplatform

    APP
    Nuvationenergy
    2.3.8 – 2.5.1 (excl.)
  • Nuvationenergy Nuvmsc3 04s C

    HW
    Nuvationenergy
    all versions
  • Nuvationenergy Nuvmsc3 08s C

    HW
    Nuvationenergy
    all versions
  • Nuvationenergy Nuvmsc3 12s C

    HW
    Nuvationenergy
    all versions
  • Nuvationenergy Nuvmsc3 16s C

    HW
    Nuvationenergy
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-64121CRITICAL10.0PL ✓same product

Ominięcie uwierzytelniania w Nuvation Energy Multi-Stack Controller (MSC)

CVE-2025-64124HIGH8.7same product

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nu...

CVE-2025-64122HIGH7.2same product

Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Sign...

CVE-2025-64123HIGH7.9same product

Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network ...