CVE•Published 2025-08-17•Modified 2025-12-03•0 articles on news•5 live references•NVD data
CVE-2025-9094Thingsboard · Thingsboard
Vulnerability data via NVD (ingested)
CVSS v3.1
4.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS percentile
15
Exploit Prediction Scoring System · top 85% of all CVEs
Weaknesses (CWE)
Description
A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."
Timeline
Published 2025-08-17
Modified 2025-12-03
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2025-9094Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product + version
product:"Thingsboard Thingsboard" version:"4.1"Version-pinned fingerprint from NVD's first vulnerable CPE.
Shodan · banner/body mention
http.html:"Thingsboard"HTTP body or banner mentions "Thingsboard" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2025-9094Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2025-9094Censys host search filtered to this CVE id.
grep.app
CVE-2025-9094Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2025-9094GitHub code search for direct mentions.
Google dork
"CVE-2025-9094" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (3)
CVE-2025-90943 repos
wolfSSL/Arduino-wolfSSLC
This repository is a restructured copy of https://github.com/wolfSSL/wolfssl/ for the Arduino environment. Any Pull Requests for code changes should be opened there.
SCGIS-Wales/ebpf-tls-tracerC
An eBPF-based tool for intercepting and inspecting TLS/SSL traffic in real time on Linux. Ships as a CLI binary, a container image and a Helm chart for Kubernetes DaemonSet deploym…
Darkham42/starsunknown
We haven't classified any articles referencing CVE-2025-9094 yet. The external references above still apply.