An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).
History

Wed, 23 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Weidmueller
Weidmueller ie-sr-2tx-wl
Weidmueller ie-sr-2tx-wl-4g-eu
Weidmueller ie-sr-2tx-wl-4g-us-v
Vendors & Products Weidmueller
Weidmueller ie-sr-2tx-wl
Weidmueller ie-sr-2tx-wl-4g-eu
Weidmueller ie-sr-2tx-wl-4g-us-v

Wed, 23 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 08:30:00 +0000

Type Values Removed Values Added
Description An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).
Title Weidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting Endpoint
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2025-07-23T08:23:28.046Z

Updated: 2025-07-23T14:04:20.683Z

Reserved: 2025-04-16T11:17:48.309Z

Link: CVE-2025-41684

cve-icon Vulnrichment

Updated: 2025-07-23T14:04:17.981Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-23T09:15:25.747

Modified: 2025-07-25T15:29:44.523

Link: CVE-2025-41684

cve-icon Redhat

No data.