CVE-2025-60036: High severity Rexroth IndraWorks vulnerability
A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the application to deserialize the malicious data, enabling Remote Code Execution (RCE). This can lead to a complete compromise of the system running the UA.Testclient.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60036?
CVE-2025-60036 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-60036?
To fix CVE-2025-60036, upgrade Rexroth IndraWorks to version 15V24 or later.
What versions of Rexroth IndraWorks are affected by CVE-2025-60036?
All versions of Rexroth IndraWorks prior to 15V24 are affected by CVE-2025-60036.
What kind of attack can be executed through CVE-2025-60036?
CVE-2025-60036 allows an attacker to execute arbitrary code on the user's system.
What is the attack vector for CVE-2025-60036?
The attack vector for CVE-2025-60036 involves parsing a manipulated file containing malicious serialized data.