<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Smartbedded</title><description>Actively exploited vulnerabilities affecting Smartbedded products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/smartbedded.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-4008 — Smartbedded Meteobridge Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-4008</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-4008</guid><description>Meteobridge is a weather data bridging device used to connect personal weather stations to online services. This vulnerability allows an unauthenticated attacker over the network to inject arbitrary commands that execute with root-level privileges — the highest access level on the device. Successful exploitation means complete device compromise, with no login required. Affected organizations using Meteobridge hardware should treat this as a critical exposure, particularly if the device management interface is reachable from untrusted networks.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>Smartbedded</category><category>Meteobridge</category></item></channel></rss>