PatchSiren cyber security CVE debrief
CVE-2025-30507 CyberData CVE debrief
CVE-2025-30507 is a medium-severity information-disclosure issue in CyberData’s 011209 SIP Emergency Intercom. According to the CISA CSAF advisory, an unauthenticated attacker can use blind SQL injection to gather sensitive information from affected devices running versions earlier than 22.0.1. The vendor’s remediation is to update to v22.0.1.
- Vendor
- CyberData
- Product
- 011209 SIP Emergency Intercom
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-05
- Original CVE updated
- 2025-06-05
- Advisory published
- 2025-06-05
- Advisory updated
- 2025-06-05
Who should care
Organizations operating CyberData 011209 SIP Emergency Intercom devices, especially if they are reachable from untrusted networks or used in facilities where emergency communications are important. Security teams, OT/ICS administrators, and asset owners should prioritize exposed or broadly accessible deployments.
Technical summary
The advisory identifies an unauthenticated blind SQL injection condition in CyberData 011209 SIP Emergency Intercom versions <22.0.1. The CVSS v3.1 vector provided by the source is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating network-reachable, low-complexity exploitation with no authentication or user interaction required and a confidentiality impact limited to sensitive information disclosure.
Defensive priority
Medium. Treat as higher priority for any deployment exposed to untrusted networks because the issue is unauthenticated and network-reachable, even though the reported impact is limited to confidentiality.
Recommended defensive actions
- Update CyberData 011209 SIP Emergency Intercom to version 22.0.1 or later as recommended by the vendor.
- Identify all deployed instances of the affected product and confirm whether any are running versions earlier than 22.0.1.
- Restrict network access to the device interface using allowlists, VLAN segmentation, or other access controls where appropriate.
- Review exposure paths for any internet-facing or broadly reachable deployments and remove unnecessary access.
- Monitor device and gateway logs for unusual requests or unexpected database-related errors where logging is available.
- Validate that emergency intercom management interfaces are not reachable from untrusted networks unless required.
- Track CISA and vendor advisories for any follow-on guidance or additional affected versions.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-25-155-01 for CVE-2025-30507, published and modified on 2025-06-05. The advisory states that CyberData 011209 SIP Emergency Intercom versions before 22.0.1 may allow an unauthenticated user to gather sensitive information through blind SQL injections, and it recommends updating to v22.0.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-30507 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-30507
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-30507 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30507
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-155-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.