CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-32409: Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be...

8.1 CVSS

Description

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.

Classification

CVE ID: CVE-2025-32409

CVSS Base Severity: HIGH

CVSS Base Score: 8.1

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem Types

CWE-23 Relative Path Traversal

Affected Products

Vendor: Ratta

Product: SuperNote A6 X2 Nomad

Exploit Prediction Scoring System (EPSS)

EPSS Score: 1.33% (probability of being exploited)

EPSS Percentile: 78.8% (scored less or equal to compared to others)

EPSS Date: 2025-05-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-32409
https://www.prizmlabs.io/post/remote-rootkits-uncovering-a-0-click-rce-in-the-supernote-nomad-e-ink-tablet

Timeline