CVE Database
/

CVE-2025-11571

Back to search

CVE-2025-11571

Published: Mar 24, 2026

Modified: Mar 24, 2026

PUBLISHED

Description

Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The commands allowed to execute can open executables. However, the commands cannot pass parameters or arguments.  To successfully execute this attack, the attacker needs to be on the same network.

VendorProductVersions

silabs.com

Simplicity Studio v5

affected
0 - <= 5.11.2.1

silabs.com

Simplicity Installer tool (Silicon Labs Tool - SLT) for Simplicity Studio v6

affected
0 - <= 1.0.1

Weaknesses (CWE)

References

https://community.silabs.com/068Vm00000htltZ
permissions-required
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now