CVE-2025-24344: Medium severity bosch ctrlx os vulnerability
A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the context of another user's browser via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24344?
CVE-2025-24344 is categorized as a critical vulnerability due to the potential for remote code execution via malicious crafted requests.
How do I fix CVE-2025-24344?
To resolve CVE-2025-24344, apply the latest security patches provided by Bosch for the ctrlX OS.
Who is affected by CVE-2025-24344?
The vulnerability affects users of Bosch ctrlX OS, specifically those using its web application.
What type of attack can exploit CVE-2025-24344?
CVE-2025-24344 can be exploited through crafted HTTP requests that inject arbitrary HTML tags into error messages.
Is authentication required to exploit CVE-2025-24344?
No, exploitation of CVE-2025-24344 can be performed by a remote unauthenticated attacker.