External risk intelligence

Nuvation Energy Multi-Stack Controller OS Command Injection.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-64120

The Nuvation Energy Multi-Stack Controller is an industrial energy management device. While these controllers often reside within private operational technology (OT) networks, they are designed to be networked and may be exposed to the internet in some deployments for remote monitoring or management, though public exposure is not the default or intended standard configuration.

OS Command Injection

Nuvationenergy Nplatform

2.3.8 to before 2.5.1

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Nuvation Energy's Multi-Stack Controller (MSC) technology, which is used in energy management systems. This issue could allow unauthorized access and control of these critical operational systems if exploited. The primary concern is to confirm if your organization uses this specific technology and is therefore potentially exposed.

  • Special commands could control the system.
  • Critical infrastructure systems rely on these controllers.
  • Confirm relevance and exposure to this technology.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input to the Nuvation Energy Multi-Stack Controller over a network. This input would be processed by the controller, leading to the execution of arbitrary operating system commands. The ability to inject and execute commands could allow an attacker to compromise the controller and potentially gain further access to the industrial control system environment.

  • Network access required.
  • Specially crafted input triggers vulnerability.
  • OS command injection leading to compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary operating system commands on the affected controller. This could occur when the controller processes specially crafted input, potentially leading to unauthorized access or modification of system functions.

  • System commands and configurations.
  • Via specially crafted input to the controller.
  • Compromise of device operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Nuvation Energy Multi-Stack Controller is likely managed by infrastructure or platform teams responsible for operational technology environments. The first critical step is to identify all deployed instances of the affected technology, confirm their network exposure and business criticality, and then locate the accountable owner to initiate a risk-based remediation plan.

  • Identify affected controllers and owners.
  • Verify network reachability and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Nuvation Energy Multi-Stack Controller?

The Multi-Stack Controller (MSC) is an industrial device built on the nPlatform. It acts as an intelligent management hub for energy storage systems, coordinating battery stacks to ensure stable, reliable power output in demanding operational environments.

How does CVE-2025-64120 enable OS Command Injection?

This vulnerability stems from CWE-78, where the software fails to properly sanitize user-provided input. Because the system treats this input as executable code, an attacker can manipulate the controller into running unauthorized operating system commands.

Does any network traffic trigger this vulnerability?

No, a generic network connection is not sufficient. The vulnerability requires the attacker to send specifically crafted input that the controller processes improperly. Normal, expected communication or administrative traffic does not inherently trigger this flaw.

Is my device at risk based on Halo Surface Signal?

While the Multi-Stack Controller is typically used in private operational networks, Halo Surface Signal notes it is a networked device. It is at higher risk if your specific deployment allows internet-based access for remote monitoring, rather than keeping the device isolated.

What steps should I take if I use an affected controller?

First, inventory your systems to confirm if you are running versions 2.3.8 through 2.5.0. Once identified, map these devices to their specific network locations and business functions to prioritize your patch management and isolation efforts accordingly.

References