CVE-2025-41651: Weidmueller: Missing Authentication Vulnerability in Industrial Ethernet Switches
Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41651?
CVE-2025-41651 is considered a critical severity vulnerability due to the potential for complete system compromise.
How do I fix CVE-2025-41651?
To mitigate CVE-2025-41651, ensure that proper authentication mechanisms are implemented for the affected functions of the device.
What devices are affected by CVE-2025-41651?
CVE-2025-41651 affects Weidmueller Industrial Ethernet Switches.
What types of attacks can be executed due to CVE-2025-41651?
An unauthenticated remote attacker can execute arbitrary commands, leading to unauthorized upload or download of configuration files.
What are the potential consequences of CVE-2025-41651?
The consequences of CVE-2025-41651 include full system compromise, allowing attackers to manipulate device functionality.