S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Aug 8, 2025

CVE-2025-8286 Scanner

CVE-2025-8286 Scanner - Unauthenticated Access vulnerability in GUralp Systems FMUS Series

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-8286
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Güralp FMUS Seriesby Güralp Systems
All versions
MIN Series Devicesby Güralp Systems
All versions
Updated Aug 22, 2026View on NVD →
Detail

The GUralp Systems FMUS Series is a range of seismic monitoring devices widely used by geophysical institutions, research bodies, and infrastructure monitoring services. These devices are employed to capture seismic events accurately, providing real-time data for analysis in monitoring and research environments. They are integral in critical infrastructure for predicting and forecasting seismic activity and helping in disaster preparedness. Due to their critical role in capturing precise seismic data, maintaining device integrity and security is paramount for users around the world. Researchers and professionals in the field use this hardware for continuous data monitoring in various environmental conditions. Their deployment in sensitive areas makes them a crucial part of safeguarding infrastructure and human safety.

This vulnerability allows unauthenticated access to the Telnet-based command line interface on GUralp Systems FMUS Series devices. Through this access, attackers can potentially modify the device's hardware configurations, manipulate critical data, or perform a factory reset. The lack of proper authentication controls leaves these devices open to exploitation by unauthorized users. As they are integral to seismic monitoring, any unauthorized manipulation can lead to significant data inaccuracies. The access is through an open interface, without requiring any prior privilege or user authentication, making it easy to exploit. Proper mitigation strategies are crucial to securing these devices from potential threats.

The technical details of the vulnerability highlight that attackers exploit an unauthenticated Telnet interface exposed by the FMUS Series devices. This interface listens on port 4244, allowing a connection without any credential check. Once connected, the interface provides a "Welcome" message and access to the command list, which can alter device configurations. The vulnerability resides in the default configuration that does not enforce authentication or encryption to protect data transit. The issue is exacerbated by the default settings that allow such access without any deterrents, posing severe security concerns. Security layers are required to shield this critical interface from unauthorized access.

When exploited, this vulnerability can have multiple detrimental effects. An attacker could significantly disrupt seismic monitoring activities by modifying data or resetting the device to factory conditions, disrupting settings necessary for precise monitoring. Such unauthorized access might lead to data inaccuracies that can impair decisions based on seismic activity, potentially affecting disaster readiness and response. These devices' role in infrastructure monitoring means such impacts could lead to significant public safety threats. Further, exploitation could lead to loss of trust in the monitoring infrastructure's integrity, affecting ongoing and future research and financial investments.

REFERENCES

Solution Advice
  • Update to the latest firmware version provided by GUralp Systems.
  • Apply recommended security patches and configurations to secure Telnet access.
  • Disable unnecessary Telnet access and use secure protocols like SSH wherever possible.
  • Implement network segmentation to limit device access within authorized zones only.
  • Regularly monitor and audit device configurations to detect unauthorized changes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.