---
id: CVE-2025-52548
title: >-
  E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API
  call in the application services that enables SSH and Shellinabox, which exist
  but are disabled by default
summary: >-
  E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API
  call in the application services that enables SSH and Shellinabox, which exist
  but are disabled by default. An attacker with admin access to the application
  se…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-1242
vendor: copeland
product: e3_supervisory_controller_firmware
affected:
  - e3_supervisory_controller_firmware < 2.31f01
patched:
  - e3_supervisory_controller_firmware 2.31f01
published: '2025-09-02'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52548'
references:
  - url: 'https://www.armis.com/research/frostbyte10/'
    label: dd59f033-460c-4b88-a075-d4d3fedb6191
tags:
  - nvd
epss: 0.00341
epssPercentile: 0.25117
ingestedAt: '2026-09-30T23:29:32.353Z'
---

## Overview

E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.

## Affected

- `e3_supervisory_controller_firmware < 2.31f01`

## Remediation

Upgrade past the affected range:

- `e3_supervisory_controller_firmware 2.31f01`
