PatchSiren cyber security CVE debrief
CVE-2025-48733 DuraComm Corporation CVE debrief
CVE-2025-48733 is a high-severity availability issue in DuraComm’s SPM-500 DP-10iN-100-MU. CISA says the affected product lacks access controls for a function that should require user authentication, which could allow an attacker to repeatedly reboot the device. DuraComm recommends updating to Version 4.10A.
- Vendor
- DuraComm Corporation
- Product
- SPM-500 DP-10iN-100-MU
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-22
- Original CVE updated
- 2025-07-22
- Advisory published
- 2025-07-22
- Advisory updated
- 2025-07-22
Who should care
OT/ICS asset owners, control system operators, network defenders, and incident responders responsible for DuraComm SPM-500 DP-10iN-100-MU deployments—especially where device uptime and availability are operationally critical.
Technical summary
The supplied CSAF record for ICSA-25-203-01 maps CVE-2025-48733 to DuraComm Corporation SPM-500 DP-10iN-100-MU versions <=4.10. The advisory description states that a function requiring authentication lacks access controls, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects a network-reachable, no-authentication availability impact consistent with repeated reboot/denial-of-service behavior.
Defensive priority
High
Recommended defensive actions
- Identify whether any DuraComm Corporation SPM-500 DP-10iN-100-MU installations are running firmware version 4.10 or earlier.
- Apply DuraComm’s recommended update to Version 4.10A; obtain the update through DuraComm’s contact channel if needed.
- Limit exposure of the device to trusted management networks and restrict administrative access to essential users and systems.
- Monitor affected environments for unexpected reboot events and validate recovery procedures for operational continuity.
- Follow CISA ICS recommended practices for segmentation and defensive hardening in OT/ICS environments.
Evidence notes
Primary evidence comes from the supplied CISA CSAF advisory record for ICSA-25-203-01 / CVE-2025-48733, published 2025-07-22 with initial revision history only. The record names the affected product as DuraComm Corporation SPM-500 DP-10iN-100-MU: <=4.10 and states that the product lacks access controls for a function that should require user authentication, allowing repeated reboot of the device. The mitigation field recommends updating to Version 4.10A. The supplied record also provides the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating availability-only impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-48733 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-48733
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-48733 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-48733
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-203-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-203-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.