CVE-2025-41719
8.8Sauter · modulo 6 and EY-modulo 5 series
A low-privileged remote attacker can corrupt device user storage by injecting unsupported characters, resulting in user deletion and the unauthorized creation of a default administrator account.
Executive summary
A vulnerability in Sauter building automation controllers allows low-privileged remote attackers to reset administrative access by corrupting device user storage.
Vulnerability
This flaw involves improper validation of syntactic correctness of input (CWE-1286). A low-privileged authenticated attacker can trigger this vulnerability via the web interface to delete existing users and force the device to revert to default administrative credentials.
Business impact
The ability for an attacker to reset administrative access poses a severe threat to the integrity and availability of building management systems. With a CVSS score of 8.8, this high-severity vulnerability could lead to unauthorized control over physical infrastructure, potential data compromise, and significant operational disruption if unauthorized administrative access is achieved.
Remediation
Immediate Action: Update affected Sauter modulo 6 and EY-modulo 5 devices to the firmware versions specified in the vendor security advisory (v3.2.0 for modulo 6 and v6.0 for EY-modulo 5).
Proactive Monitoring: Review device access logs for unusual administrative login patterns or unexpected modifications to the user database.
Compensating Controls: Restrict network access to the device web interface to trusted management subnets and deploy a Web Application Firewall to filter malicious character sequences.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total loss of administrative control, organizations utilizing Sauter automation controllers should prioritize the application of the vendor-provided firmware patches. Ensure that these devices are isolated from the public internet and that administrative interfaces are restricted to authorized personnel only to minimize the attack surface.
Sources
Originally found and disclosed by Damian Pfammatter, Daniel Hulliger from Cyber-Defence Campus armasuisse, per the CVE Program record.