CISA Alert: Critical Flaw (CVE-2025-8286) in Güralp FMUS Seismic Devices Allows Unauthenticated Takeover, No Patch!
ID: 511e51de-7a60-53df-9eaa-d1669073345d
STIX ID: report--511e51de-7a60-53df-9eaa-d1669073345d
Feed Name: securityonline.info
CISA issued an urgent advisory for CVE-2025-8286 affecting all Güralp FMUS seismic monitoring devices: an exposed, unauthenticated Telnet command-line interface (CVSS 9.8) could permit remote actors to reconfigure hardware, manipulate seismic data, or factory-reset devices. Güralp did not respond to coordination requests; CISA recommends minimizing network exposure, isolating control networks behind firewalls, using secure VPN access, and monitoring for malicious activity until a vendor patch is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
