CVE-2025-41662: Weidmueller: Security routers IE-SR-2TX are affected by Cross-Site Request Forgery

Published Jun 11, 2025
·
Updated

Rejected reason: CVE-2025-41662 is considered redundant or unnecessary and thus should be withdrawn. Instead, a new CVE CVE-2025-41687 has been reserved to better reflect the updated analysis.

Affected Software

1 affected component
Weidmueller IE-SR-2TX

Event History

Jun 11, 2025
CVE Published
via MITRE·08:08 AM
Rejected
via MITRE·08:08 AM
Data Sourced
via NVD·09:15 AM
Description
Jul 23, 2025
Rejected
via MITRE·07:53 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-41662?

CVE-2025-41662 is considered a critical vulnerability due to the potential for unauthenticated remote command execution with root privileges.

2

How do I fix CVE-2025-41662?

To mitigate CVE-2025-41662, ensure that your devices are updated with the latest patches from Weidmueller that address the CSRF vulnerability.

3

What should I do if I am using Weidmueller IE-SR-2TX regarding CVE-2025-41662?

If you are using Weidmueller IE-SR-2TX, review your device settings and apply recommended security updates to protect against CVE-2025-41662.

4

Can CVE-2025-41662 affect my system if it is behind a firewall?

While a firewall can provide a layer of security, CVE-2025-41662 can still pose a risk if the system is exposed to untrusted networks or services.

5

What exploitation methods are available for CVE-2025-41662?

CVE-2025-41662 can be exploited via crafted requests that allow attackers to bypass CSRF protections, targeting the main web interface of affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203