CVE-2025-41649: Weidmueller: Out-of-Bounds Write Vulnerability in Industrial Ethernet Switches
Published May 27, 2025
·Updated
An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer, potentially leading to a denial-of-service condition for the devices.
Affected Software
1 affected component
Weidmueller Industrial Ethernet Switches
Event History
May 27, 2025
CVE Published
via MITRE·08:37 AM
Data Sourced
via MITRE·08:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41649?
CVE-2025-41649 is categorized as a high-severity vulnerability due to its potential to cause denial-of-service conditions.
2
How can I mitigate the risk of CVE-2025-41649?
To mitigate CVE-2025-41649, ensure that all firmware for Weidmueller Industrial Ethernet Switches is updated to the latest version.
3
What kind of attack can CVE-2025-41649 enable?
CVE-2025-41649 can enable an unauthenticated remote attacker to exploit insufficient input validation and write beyond buffer limits.
4
Which devices are affected by CVE-2025-41649?
CVE-2025-41649 specifically affects Weidmueller Industrial Ethernet Switches.
5
Is authentication required to exploit CVE-2025-41649?
No, CVE-2025-41649 can be exploited by an unauthenticated remote attacker.