CVE-2025-41684: Weidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting Endpoint
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tlsiotgensetting).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41684?
CVE-2025-41684 is rated as critical due to its potential to allow authenticated attackers to execute arbitrary commands with root privileges.
How do I fix CVE-2025-41684?
To fix CVE-2025-41684, you should update the affected devices with the latest security patches provided by Weidmueller.
What is the vulnerability CVE-2025-41684 about?
CVE-2025-41684 involves insufficient input sanitization in the Main Web Interface, enabling remote attackers to inject and execute commands.
Who is affected by CVE-2025-41684?
CVE-2025-41684 affects devices using the Weidmueller Root Command Injection software that lacks proper input validation.
Can CVE-2025-41684 be exploited remotely?
Yes, CVE-2025-41684 can be exploited remotely by authenticated attackers who exploit the vulnerability through the web interface.