PatchSiren cyber security CVE debrief
CVE-2025-24861 Outback Power CVE debrief
CVE-2025-24861 covers a command injection issue in the Outback Power Mojave Inverter. CISA’s advisory says an attacker may inject commands via specially crafted POST requests, and the supplied remediation recommends disabling the product’s networking features until a replacement can be acquired. The advisory was published on 2025-02-13 and the supplied metadata does not list the issue in CISA’s Known Exploited Vulnerabilities catalog.
- Vendor
- Outback Power
- Product
- Mojave Inverter
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-13
- Original CVE updated
- 2025-02-13
- Advisory published
- 2025-02-13
- Advisory updated
- 2025-02-13
Who should care
Industrial control system owners, site operators, and defenders responsible for Outback Power Mojave Inverter deployments should prioritize this advisory. It is especially relevant where the device is network-reachable or exposed beyond a tightly controlled OT segment.
Technical summary
The supplied CISA CSAF advisory (ICSA-25-044-17) describes a command injection condition in the Outback Power Mojave Inverter where an attacker may inject commands via specially crafted POST requests. The affected product entry is listed as vers:all/*, indicating all versions represented in the advisory scope. The provided CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, which aligns with a network-reachable issue requiring no privileges or user interaction and causing high confidentiality impact. CISA’s remediation note states that the product may be discontinued and recommends disabling networking features until a replacement product can be acquired.
Defensive priority
High. This is a remotely reachable OT/ICS issue with no privileges or user interaction required, so exposed deployments should be treated as urgent to isolate and mitigate.
Recommended defensive actions
- Disable the Mojave Inverter’s networking features as CISA recommends, if operationally possible.
- Remove or restrict any network exposure to the device, especially from untrusted or routed networks.
- Inventory all Outback Power Mojave Inverter deployments and confirm whether they match the affected advisory scope.
- Use OT network segmentation and access control to minimize who can reach the device.
- Plan for replacement if the product is no longer maintained or supported.
- Monitor the CISA advisory for updates and any future vendor guidance.
Evidence notes
All material facts in this debrief come from the supplied CISA CSAF source item for ICSA-25-044-17 and the embedded remediation note. The advisory text explicitly states that an attacker may inject commands via specially crafted POST requests, and the remediation text explicitly recommends disabling networking features until a replacement product can be acquired.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-24861 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-24861
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-24861 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24861
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-17.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-17
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.