CVE-2025-41683

8.8

Weidmueller · IE-SR-2TX-WL series

An authenticated remote command injection vulnerability in the Weidmueller web interface allows attackers with low privileges to execute arbitrary commands as root via the event_mail_test endpoint.

Executive summary

An authenticated remote command injection vulnerability in Weidmueller industrial devices allows attackers to gain root-level access and compromise the entire system.

Vulnerability

This is an OS Command Injection (CWE-78) vulnerability occurring within the Main Web Interface at the event_mail_test endpoint. An authenticated attacker can leverage this flaw to execute arbitrary system commands with root privileges.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected industrial device. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized data access, complete system compromise, and potential disruption of critical industrial processes.

Remediation

Immediate Action: Apply the vendor-provided security updates identified in the VDE-2025-052 advisory as soon as they become available. Ensure all devices are upgraded to at least version V1.49 or V1.62 respectively.

Proactive Monitoring: Monitor system logs for unusual activity, specifically looking for unexpected command execution patterns or unauthorized attempts to access the event_mail_test endpoint.

Compensating Controls: Restrict access to the device management interface to trusted administrative networks only and implement strict firewall rules to prevent unauthorized users from reaching the web interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the potential for full system compromise, IT and OT security teams must prioritize this vulnerability. Once the vendor releases the necessary firmware updates, they should be tested and deployed immediately to eliminate the root command injection vector.

More Weidmueller CVEs

Sources

Originally found and disclosed by Reid Wightman of Dragos Inc., per the CVE Program record.