ZDI-26-108: Bosch Rexroth IndraWorks UA.TestClient XML File Parsing Deserialization Of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bosch Rexroth IndraWorks. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-60036.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-108?
The severity of ZDI-26-108 is rated at 7.8, indicating a high risk for affected systems.
How do I fix ZDI-26-108?
To fix ZDI-26-108, apply the latest patches released by Bosch Rexroth for IndraWorks.
What type of vulnerability is ZDI-26-108?
ZDI-26-108 is a deserialization vulnerability that can lead to remote code execution.
Who is affected by ZDI-26-108?
Organizations using Bosch Rexroth IndraWorks software are affected by ZDI-26-108.
What does ZDI-26-108 exploit require from users?
ZDI-26-108 requires user interaction, such as visiting a malicious page or opening a malicious file.