CVE-2025-40746: Input Validation
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40746?
The severity of CVE-2025-40746 is considered high due to the potential for remote code execution by authenticated users.
How do I fix CVE-2025-40746?
To mitigate CVE-2025-40746, update the SIMATIC RTLS Locating Manager software to version 3.2 or later.
Who is affected by CVE-2025-40746?
CVE-2025-40746 affects all versions of SIMATIC RTLS Locating Manager prior to version 3.2.
What type of attack does CVE-2025-40746 allow?
CVE-2025-40746 allows an authenticated remote attacker to execute arbitrary code with high privileges.
What is SIMATIC RTLS Locating Manager?
SIMATIC RTLS Locating Manager is a software application used for managing and locating assets in real-time within industrial environments.