CVE-2025-41661: Weidmueller: Security routers IE-SR-2TX are affected by CSRF
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41661?
CVE-2025-41661 is considered critical as it allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
How do I fix CVE-2025-41661?
To mitigate CVE-2025-41661, ensure that your Weidmueller Security routers IE-SR-2TX are updated to the latest firmware version that addresses this vulnerability.
What devices are affected by CVE-2025-41661?
CVE-2025-41661 affects Weidmueller Security routers IE-SR-2TX, which lack CSRF protection.
Can CVE-2025-41661 be exploited remotely?
Yes, CVE-2025-41661 can be exploited remotely by unauthenticated attackers.
What is the nature of the vulnerability in CVE-2025-41661?
CVE-2025-41661 is due to a lack of Cross-Site Request Forgery (CSRF) protection in the Main Web Interface, specifically at the endpoint event_mail_test.