CVE-2025-41663: Weidmueller: Security routers IE-SR-2TX are affected by Command Injection
For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then executed with elevated privileges. To get into such a position, clients would need to use insecure proxy configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41663?
CVE-2025-41663 is considered a critical vulnerability due to its potential for command injection and arbitrary command execution.
How do I fix CVE-2025-41663?
To fix CVE-2025-41663, ensure that all WWH servers are updated to the latest firmware version that patches this vulnerability.
Who is affected by CVE-2025-41663?
CVE-2025-41663 primarily affects users of the Weidmueller IE-SR-2TX device that utilize WWH servers.
What kind of attack can exploit CVE-2025-41663?
CVE-2025-41663 can be exploited through man-in-the-middle attacks allowing an unauthenticated attacker to inject commands.
What are the potential impacts of CVE-2025-41663?
The potential impacts of CVE-2025-41663 include unauthorized command execution and elevated privileges leading to system compromise.