Skip to main content

CVE-2025-9094: ThingsBoard Template Injection RCE Vulnerability

CVE-2025-9094 is a remote code execution vulnerability in ThingsBoard 4.1 affecting the Add Gateway Handler component through template injection. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-9094 Overview

CVE-2025-9094 is a template injection vulnerability affecting ThingsBoard version 4.1, an open-source Internet of Things (IoT) platform. The flaw resides in the Add Gateway Handler component and stems from improper neutralization of special elements used in a template engine [CWE-791]. An authenticated remote attacker can submit crafted input that the template engine interprets as code rather than data. The vendor confirmed a fix will ship in version 4.2 and be back-ported to maintenance releases of long-term support (LTS) branches starting at 4.0. Public disclosure of exploit details has occurred.

Critical Impact

Authenticated attackers can abuse the Add Gateway Handler to inject template expressions that affect integrity of application-rendered output in thingsboard 4.1.

Affected Products

  • ThingsBoard 4.1 (cpe:2.3:a:thingsboard:thingsboard:4.1:*:*:*:*:*:*:*)
  • ThingsBoard LTS maintenance branches starting at 4.0 (fix inherited)
  • Deployments exposing the Add Gateway Handler to low-privileged users

Discovery Timeline

  • 2025-08-17 - CVE-2025-9094 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-9094

Vulnerability Analysis

The weakness is a server-side template injection (SSTI) in the Add Gateway Handler component of ThingsBoard 4.1. User-controlled input flows into a template engine without adequate sanitization of control characters or expression delimiters. When the engine renders the template, attacker-supplied expressions are evaluated instead of being treated as literal text. The attack requires low privileges and no user interaction, and it can be launched over the network.

According to the vendor statement captured in the advisory, the issue will be remediated in ThingsBoard 4.2 and inherited by LTS maintenance releases starting at 4.0. Exploit details are public, though no entry exists on the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog.

Root Cause

The root cause maps to [CWE-791] Incomplete Filtering of Special Elements. The Add Gateway Handler accepts input used to build a template, but the application does not strip or escape template-specific metacharacters before passing the value to the rendering engine. This allows the engine to parse attacker-supplied syntax as executable template directives.

Attack Vector

An authenticated user with permission to add or configure a gateway submits a crafted payload containing template expression delimiters. The ThingsBoard backend passes that payload to the template engine, which evaluates the embedded expressions. Observed impact is limited to integrity of rendered content; confidentiality and availability are not scored as impacted under the CVSS 4.0 vector supplied with the record.

No verified proof-of-concept code is available in the referenced sources. See the VulDB entry #320416 and the linked disclosure document for the public write-up.

Detection Methods for CVE-2025-9094

Indicators of Compromise

  • Gateway configuration objects containing template delimiters such as ${...}, {{...}}, or #{...} in name or metadata fields.
  • Application logs showing template engine evaluation errors originating from the Add Gateway Handler endpoint.
  • Unexpected changes to gateway entities authored by low-privileged tenant users.

Detection Strategies

  • Inspect ThingsBoard REST API traffic for POST requests to gateway creation endpoints containing template metacharacters in parameter values.
  • Review audit logs for Add Gateway operations submitted by non-administrative accounts and correlate with rendering errors.
  • Hunt across historical gateway records for stored payloads that match template expression syntax.

Monitoring Recommendations

  • Forward ThingsBoard application and audit logs to a centralized Security Information and Event Management (SIEM) platform for pattern analysis.
  • Alert on template engine exceptions emitted by the backend process serving the gateway API.
  • Baseline normal gateway creation volumes per tenant and flag deviations.

How to Mitigate CVE-2025-9094

Immediate Actions Required

  • Inventory all ThingsBoard deployments and identify instances running version 4.1.
  • Restrict Add Gateway permissions to trusted administrative roles until a fixed release is applied.
  • Audit existing gateway records for stored template expressions and remove or sanitize suspicious entries.
  • Place the ThingsBoard management interface behind network segmentation that limits access to known operators.

Patch Information

The vendor stated the fix will ship in ThingsBoard 4.2 and will be inherited by maintenance releases of LTS versions starting at 4.0. Monitor the ThingsBoard release channels and apply the fixed version as soon as it becomes available. Track VulDB CTI #320416 for updates to the public record.

Workarounds

  • Enforce role-based access control (RBAC) so only vetted accounts can invoke the Add Gateway Handler.
  • Apply a reverse-proxy or Web Application Firewall (WAF) rule that blocks template delimiter sequences in gateway creation requests.
  • Validate tenant-submitted gateway names and metadata against an allow-list of alphanumeric characters before storage.
bash
# Example WAF rule concept: block template delimiters in Add Gateway requests
# (adapt to your WAF syntax; this is illustrative, not production-ready)
SecRule REQUEST_URI "@contains /api/gateway" \
  "chain,id:900094,phase:2,deny,status:400,msg:'CVE-2025-9094 template delimiters blocked'"
  SecRule ARGS "@rx (\$\{|\{\{|#\{)" "t:none"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.