PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-48733 DuraComm Corporation CVE debrief

CVE-2025-48733 is a high-severity availability issue in DuraComm’s SPM-500 DP-10iN-100-MU. CISA says the affected product lacks access controls for a function that should require user authentication, which could allow an attacker to repeatedly reboot the device. DuraComm recommends updating to Version 4.10A.

Vendor
DuraComm Corporation
Product
SPM-500 DP-10iN-100-MU
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-22
Original CVE updated
2025-07-22
Advisory published
2025-07-22
Advisory updated
2025-07-22

Who should care

OT/ICS asset owners, control system operators, network defenders, and incident responders responsible for DuraComm SPM-500 DP-10iN-100-MU deployments—especially where device uptime and availability are operationally critical.

Technical summary

The supplied CSAF record for ICSA-25-203-01 maps CVE-2025-48733 to DuraComm Corporation SPM-500 DP-10iN-100-MU versions <=4.10. The advisory description states that a function requiring authentication lacks access controls, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects a network-reachable, no-authentication availability impact consistent with repeated reboot/denial-of-service behavior.

Defensive priority

High

Recommended defensive actions

  • Identify whether any DuraComm Corporation SPM-500 DP-10iN-100-MU installations are running firmware version 4.10 or earlier.
  • Apply DuraComm’s recommended update to Version 4.10A; obtain the update through DuraComm’s contact channel if needed.
  • Limit exposure of the device to trusted management networks and restrict administrative access to essential users and systems.
  • Monitor affected environments for unexpected reboot events and validate recovery procedures for operational continuity.
  • Follow CISA ICS recommended practices for segmentation and defensive hardening in OT/ICS environments.

Evidence notes

Primary evidence comes from the supplied CISA CSAF advisory record for ICSA-25-203-01 / CVE-2025-48733, published 2025-07-22 with initial revision history only. The record names the affected product as DuraComm Corporation SPM-500 DP-10iN-100-MU: <=4.10 and states that the product lacks access controls for a function that should require user authentication, allowing repeated reboot of the device. The mitigation field recommends updating to Version 4.10A. The supplied record also provides the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating availability-only impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-48733 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-48733

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-48733 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-48733

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-203-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-203-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.