CVE-2025-9094 Overview
CVE-2025-9094 is a template injection vulnerability affecting ThingsBoard version 4.1, an open-source Internet of Things (IoT) platform. The flaw resides in the Add Gateway Handler component and stems from improper neutralization of special elements used in a template engine [CWE-791]. An authenticated remote attacker can submit crafted input that the template engine interprets as code rather than data. The vendor confirmed a fix will ship in version 4.2 and be back-ported to maintenance releases of long-term support (LTS) branches starting at 4.0. Public disclosure of exploit details has occurred.
Critical Impact
Authenticated attackers can abuse the Add Gateway Handler to inject template expressions that affect integrity of application-rendered output in thingsboard 4.1.
Affected Products
- ThingsBoard 4.1 (cpe:2.3:a:thingsboard:thingsboard:4.1:*:*:*:*:*:*:*)
- ThingsBoard LTS maintenance branches starting at 4.0 (fix inherited)
- Deployments exposing the Add Gateway Handler to low-privileged users
Discovery Timeline
- 2025-08-17 - CVE-2025-9094 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9094
Vulnerability Analysis
The weakness is a server-side template injection (SSTI) in the Add Gateway Handler component of ThingsBoard 4.1. User-controlled input flows into a template engine without adequate sanitization of control characters or expression delimiters. When the engine renders the template, attacker-supplied expressions are evaluated instead of being treated as literal text. The attack requires low privileges and no user interaction, and it can be launched over the network.
According to the vendor statement captured in the advisory, the issue will be remediated in ThingsBoard 4.2 and inherited by LTS maintenance releases starting at 4.0. Exploit details are public, though no entry exists on the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog.
Root Cause
The root cause maps to [CWE-791] Incomplete Filtering of Special Elements. The Add Gateway Handler accepts input used to build a template, but the application does not strip or escape template-specific metacharacters before passing the value to the rendering engine. This allows the engine to parse attacker-supplied syntax as executable template directives.
Attack Vector
An authenticated user with permission to add or configure a gateway submits a crafted payload containing template expression delimiters. The ThingsBoard backend passes that payload to the template engine, which evaluates the embedded expressions. Observed impact is limited to integrity of rendered content; confidentiality and availability are not scored as impacted under the CVSS 4.0 vector supplied with the record.
No verified proof-of-concept code is available in the referenced sources. See the VulDB entry #320416 and the linked disclosure document for the public write-up.
Detection Methods for CVE-2025-9094
Indicators of Compromise
- Gateway configuration objects containing template delimiters such as ${...}, {{...}}, or #{...} in name or metadata fields.
- Application logs showing template engine evaluation errors originating from the Add Gateway Handler endpoint.
- Unexpected changes to gateway entities authored by low-privileged tenant users.
Detection Strategies
- Inspect ThingsBoard REST API traffic for POST requests to gateway creation endpoints containing template metacharacters in parameter values.
- Review audit logs for Add Gateway operations submitted by non-administrative accounts and correlate with rendering errors.
- Hunt across historical gateway records for stored payloads that match template expression syntax.
Monitoring Recommendations
- Forward ThingsBoard application and audit logs to a centralized Security Information and Event Management (SIEM) platform for pattern analysis.
- Alert on template engine exceptions emitted by the backend process serving the gateway API.
- Baseline normal gateway creation volumes per tenant and flag deviations.
How to Mitigate CVE-2025-9094
Immediate Actions Required
- Inventory all ThingsBoard deployments and identify instances running version 4.1.
- Restrict Add Gateway permissions to trusted administrative roles until a fixed release is applied.
- Audit existing gateway records for stored template expressions and remove or sanitize suspicious entries.
- Place the ThingsBoard management interface behind network segmentation that limits access to known operators.
Patch Information
The vendor stated the fix will ship in ThingsBoard 4.2 and will be inherited by maintenance releases of LTS versions starting at 4.0. Monitor the ThingsBoard release channels and apply the fixed version as soon as it becomes available. Track VulDB CTI #320416 for updates to the public record.
Workarounds
- Enforce role-based access control (RBAC) so only vetted accounts can invoke the Add Gateway Handler.
- Apply a reverse-proxy or Web Application Firewall (WAF) rule that blocks template delimiter sequences in gateway creation requests.
- Validate tenant-submitted gateway names and metadata against an allow-list of alphanumeric characters before storage.
# Example WAF rule concept: block template delimiters in Add Gateway requests
# (adapt to your WAF syntax; this is illustrative, not production-ready)
SecRule REQUEST_URI "@contains /api/gateway" \
"chain,id:900094,phase:2,deny,status:400,msg:'CVE-2025-9094 template delimiters blocked'"
SecRule ARGS "@rx (\$\{|\{\{|#\{)" "t:none"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.