We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

PSIRT-102: TimeProvider® 4100 Grandmaster Remote Command Execution

Vulnerability Details


Date of Disclosure: 10/16/2025

Affected Product: TimeProvider® 4100 Grandmaster

  • Vulnerability Type: Remote command execution (RCE)
  • CVE Identifier: CVE-2025-47901
  • CVSS Score: 8.9 (CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
  • Vulnerability Description:
    • Authenticated users can execute arbitrary system commands through the management web interface.
  • Affected Versions: 
    • Firmware through 2.4
  • Vulnerability Status: 
    • Resolved in firmware release 2.5

Risk Assessment


Exploitation of the vulnerability could allow an attacker to execute commands on the system.

Mitigation


Do not expose the web interface on the separate management port to an untrusted network. For added security, users have the option to disable the web interface, further protecting the device from potential web-based exploitation.

Patch/Release Information


As of version 2.5, the parameter is sanitized before it is used.

Acknowledgements


Reported by Dario Emilio Bertani, Raffaele Bova, Andrea Sindoni, Simone Bossi, Antonio Carriero, Marco Manieri, Vito Pistillo, Davide Renna, Manuel Leone, Massimiliano Brolli, and TIM Security Red Team Research.

Recommendations


It is strongly recommended that all customers upgrade to version 2.5 or newer.

Title


Title
Category
DS Number
VSC8540RT IBIS Model - CQFP68 Product Documents Download
SST38LF6401RT IBIS Model - CDFP48 Product Documents Download
SAMRH71F20-EK Schematics Product Documents Download
IBIS MODEL - SST26LF064RT - SM Product Documents Download
VSC8540RT IBIS Model - VQFN68 Product Documents Download
SAMRH71F20-EK - Altium Project Product Documents Download
SAMRH71F20C Schematic Symbol Product Documents Download
SAMRH71F20C Footprint Product Documents Download
IBIS MODEL - SST26LF064RT - HHB Product Documents Download
SAMRH707F18-EK - Altium Project Product Documents Download
SST38LF6401RT IBIS Model - TSOP48 Product Documents Download
SAMRH71F20 Evaluation Kit Schematics Product Documents Download
SAMRH71F20-EK - Altium Project Product Documents Download
SAMRH71F20 TFBGA625 Footprint Product Documents Download
SAMRH71F20 TFBGA625 Schematic Symbol Product Documents Download
VSC8574RT IBIS Model - CQFP256 Product Documents Download
VSC8574RT IBIS Model - PBGA256 Product Documents Download
VSC8541RT IBIS Model - CQFP68 Product Documents Download
VSC8541RT IBIS Model - VQFN68 Product Documents Download
SAMRH707F18 CQFP164 Footprint Product Documents Download
SAMRH707F18 CQFP164 Schematic Symbol Product Documents Download
SAMRH707-EK Product Documents Download
SAMRH707-EK_V2 Product Documents Download
SAMRH707F18-EK - Altium Project - V2 Product Documents Download
SST38LF6401ET IBIS Model - TSOP48 Product Documents Download
VSC8541ET IBIS Model - VQFN68 Product Documents Download
VSC8540ET IBIS Model - VQFN68 Product Documents Download
SAMV71Q21RT CQFP144 IBIS Product Documents Download
SAMRH71F20E IBIS Models Product Documents Download
SAMRH707F18C IBIS Models Product Documents Download
SAMRH707 TFBGA EK AltiumProject Product Documents Download
SAMRH707F18 TFBGA Evaluation Kit Schematics Product Documents Download
SAMRH707F18 TFBGA Symbol Product Documents Download
SAMRH707F18 TFBGA Footprint Product Documents Download
SAMRH71F20 TFBGA625 EK Schematics Product Documents Download
SAMRH71F20 TFBGA625 EK Altium Project Product Documents Download
SAMV71Q21RT CQFP144 Footprint Product Documents Download
SAMV71Q21RT CQFP144 Schematic Symbol Product Documents Download
ATA6571RT IBIS Model - SOIC14 Product Documents Download
ATA6571RT IBIS Model - CDFP14 Product Documents Download