logo

Delving into Windows CE, Part 4: Vulnerability Research into a Windows CE-Based HMI Used in the Wild

ID: 04cc781e-a953-5a47-a2bc-b7e965cb1272

STIX ID: report--04cc781e-a953-5a47-a2bc-b7e965cb1272

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2025-05-06

Date Updated: 2026-04-17

Author: Tomer Goldschmidt

...
...

This report describes discovery and exploitation of a stack buffer overflow in the WSFTP.exe FTP server on Windows CE-based AutomationDirect C-more HMI panels, detailing firmware unpacking, vulnerable code analysis, a proof-of-concept RCE exploit (CVE-2024-25137) using wide-char payloads and ROP, the identification of ~330 exposed devices online, and coordinated disclosure with vendor patches and a CISA advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.