Close Menu
TechurzTechurz
    What's Hot

    Ozlo’s Sleepbuds 2 build on Bose’s sleep earbud legacy

    July 28, 2026

    Cursor makes its biggest India push yet ahead of SpaceX acquisition with localized pricing

    July 28, 2026

    Antares raises $470M to build nuclear reactors for the US military

    July 27, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Ozlo’s Sleepbuds 2 build on Bose’s sleep earbud legacy
    • Cursor makes its biggest India push yet ahead of SpaceX acquisition with localized pricing
    • Antares raises $470M to build nuclear reactors for the US military
    • Ilya Sutskever’s Safe Superintelligence partners with Nvidia to scale its AI research
    • Enigma raises $70M to make controlling a robot as easy as adjusting the volume
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - New Supermicro BMC vulnerabilities open servers to malicious attacks on firmware
    Cyber Reality

    New Supermicro BMC vulnerabilities open servers to malicious attacks on firmware

    TechurzBy TechurzSeptember 26, 2025Updated:May 10, 2026No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Photo of Out of Focus IT Technician Turning on Data Server.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    During this research, Binarly discovered a second vulnerability, CVE-2025-6198, relating to Supermicro’s X13SEM-F motherboard firmware, also rated as high severity with a CVSS score of 7.2.

    While CVE-2025-7937 or CVE-2025-6198 would pose major security risks in the event attackers were able to exploit them, the caveat is that to do so the attackers would need to have established admin access to the systems to interact with the firmware.

    That might make exploitation sound like a long shot — neither can be exploited remotely — but as countless real-world attacks show, rogue admin access and privilege elevation can be gained in a separate, indirect attack.

    Incomplete fix

    CVE-2025-7937 and CVE-2025-6198 uncovered different issues with Supermicro’s validation logic, the checking process that’s supposed to stop legitimate firmware being replaced with malicious code.

    Binarly said that the January flaw, CVE-2024-10237, made it possible to fool the validation process by adding illicit entries to the firmware map table (fwmap) so that the rogue firmware matched the cryptographically signed value.

    Supermicro adjusted the validation checks to detect this, but through CVE-2025-7937, Binarly researchers were able to re-target the modified validation checking.

    attacks BMC firmware Malicious Open servers Supermicro vulnerabilities
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI tested the iPhone Air for a week, and here’s why 17 Pro Max users shouldn’t sleep on it
    Next Article Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
    Techurz
    • Website

    Related Posts

    Opinion

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026
    Opinion

    Open source AI matters more than ever, according to Hugging Face’s Clem Delangue

    July 10, 2026
    Opinion

    Popular open source AI developer tool Ollama raises $65M, grows to nearly 9M users

    July 9, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.