CVE-2025-24347: Medium severity bosch ctrlx os vulnerability
Published Apr 30, 2025
·Updated
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration file via a crafted HTTP request.
Affected Software
1 affected component
Bosch ctrlX OS
Event History
Apr 30, 2025
CVE Published
via MITRE·11:41 AM
Data Sourced
via MITRE·11:41 AM
DescriptionSeverity
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24347?
CVE-2025-24347 is categorized as a low to medium severity vulnerability.
2
How do I fix CVE-2025-24347?
To fix CVE-2025-24347, ensure that the network configuration file validations are implemented to restrict unauthorized HTTP requests.
3
Who is affected by CVE-2025-24347?
CVE-2025-24347 affects users of Bosch ctrlX OS who have not secured their network interfaces.
4
Can CVE-2025-24347 be exploited remotely?
Yes, CVE-2025-24347 can be exploited remotely by low-privileged authenticated attackers.
5
What impact does CVE-2025-24347 have on network security?
CVE-2025-24347 allows attackers to manipulate network configurations, which could lead to unauthorized access or disruption of services.