← Vulnerability feed

Vulnerability record · CVE-2025-47900 · published 20 October 2025

CVE-2025-47900: Microchip timeprovider 4100 firmware os command injection vulnerability

Microchip · Timeprovider 4100 Firmware

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.

8.9 CVSS 4.0 High EPSS 1.4% · top 29.0% CWE-78 · OS command injection
8.9CVSS 4.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.

CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-47900 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.9CVE-2025-47901Microchip timeprovider 4100 firmware os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Co…EPSS 1.4%8.7CVE-2024-43683Microchip timeprovider 4100 firmware open redirect vulnerabilityURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects T…EPSS 0.23%8.7CVE-2024-43684Microchip timeprovider 4100 firmware cross-site scripting vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This iss…EPSS 0.21%8.7CVE-2024-43685Microchip timeprovider 4100 firmware insufficient session expiration vulnerabilityImproper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: f…EPSS 0.44%8.5CVE-2024-9054Microchip timeprovider 4100 firmware os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Acto…EPSS 16%7.7CVE-2024-43687Microchip timeprovider 4100 firmware cross-site scripting vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner conf…EPSS 0.83%7.1CVE-2025-47902Microchip timeprovider 4100 firmware sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injecti…EPSS 0.38%6.3CVE-2024-7801Microchip timeprovider 4100 firmware sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules)…EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2025-47900), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.