CVE-2025-11243
Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.
An unauthenticated attacker can force the device to reboot, effectively causing a denial of service (DoS).
November 18, 2025
This issue affects Shelly Pro 4PM below version 1.6
CVE-2025-11243
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
8.3
To fix this issue, it's suggested to update the Pro 4PM to v1.6
Gabriele Quagliarella of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

