CVE-2025-47901: RCE on restore configuration password
Published Oct 20, 2025
·Updated
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.
Affected Software
3 affected components
Microchip Time Provider 4100<2.5
All of the following
Microchip Timeprovider 4100 Firmware<2.5
Microchip TimeProvider 4100
Event History
Oct 20, 2025
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47901?
The severity of CVE-2025-47901 is classified as critical due to its potential for OS command injection.
2
How do I fix CVE-2025-47901?
To fix CVE-2025-47901, update the Microchip Time Provider 4100 to version 2.5 or later.
3
What systems are affected by CVE-2025-47901?
CVE-2025-47901 affects Microchip Time Provider 4100 versions prior to 2.5.
4
What risks are associated with CVE-2025-47901?
The risks associated with CVE-2025-47901 include unauthorized execution of OS commands leading to potential system compromise.
5
Is there a workaround for CVE-2025-47901?
There are no known workaround solutions for CVE-2025-47901 besides updating to the fixed version.