CVE-2025-54848Disclosure(socomec / diris_digiware_m-70)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can trigger this denial-of-service condition by sending a sequence of Modbus TCP messages to port 502 using the Write Single Register function code (6). The attack sequence begins with a message to register 58112 with a value of 1000, indicating that a configuration change will follow. Next, a message is sent to register 29440 with a value corresponding to the new Modbus address to be configured. Finally, a message to register 57856 with a value of 161 commits the configuration change. After this configuration change, the device will be in a denial-of-service state.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • diris_digiware_m-70
  • diris_digiware_m-70_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
diris_digiware_m-70diris_digiware_m-70_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-18: 1Technical Details · 2026-02-18: 102-18
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ProbablyPwned@probablypwned
    Disclosure

    Cisco Talos researcher uncovers critical vulnerabilities in Socomec DIRIS M-70 energy gateway via 'good enough' emulation, revealing CVE-2025-54848 and CVE-2025-55222 in Modbus protocol handling. Read more: https://www.probablypwned.com/article/talos-good-enough-emulation-fuzzing-socomec-modbus-cves

    Post summary

    A Cisco Talos researcher has discovered two critical vulnerabilities (CVE‑2025‑54848 and CVE‑2025‑55222) in the Socomec DIRIS M‑70 energy gateway through emulation-based fuzzing, affecting Modbus protocol handling.

    1000046
    12 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWsocomecdiris_digiware_m-70---
OSsocomecdiris_digiware_m-70_firmware1.6.9--

Explore more