CVE-2025-41726

8.8

Beckhoff Automation · Device Manager, MDP software package, MDP for Beckhoff RT Linux

An integer overflow vulnerability in Beckhoff Automation software allows low-privileged remote attackers to achieve arbitrary code execution via crafted web service or API calls.

Executive summary

A critical integer overflow vulnerability in Beckhoff Automation device management software permits remote code execution by low-privileged attackers, posing a severe threat to operational integrity.

Vulnerability

This vulnerability involves an integer overflow (CWE-190) triggered by specially crafted calls to the web service or local API. The flaw allows an attacker with low-level privileges to execute arbitrary code within the context of privileged processes.

Business impact

Successful exploitation allows an attacker to gain elevated control over affected industrial control systems or devices. Given the CVSS score of 8.8, this vulnerability represents a high risk for unauthorized system access, potential data manipulation, or complete disruption of industrial operations. Organizations relying on these components face significant operational risk if these systems are accessible via network interfaces.

Remediation

Immediate Action: Update the affected Beckhoff Automation software components to the versions specified in the vendor security advisory (VDE-2025-092).

Proactive Monitoring: Monitor network traffic and system logs for anomalous API calls or unexpected processes spawned by the Device Manager service.

Compensating Controls: Restrict network access to the Device Manager web service and API to trusted management workstations only, utilizing firewall rules to minimize the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high CVSS score of 8.8 underscores the urgency of addressing this flaw. System administrators should prioritize testing and deploying the provided patches to ensure that low-privileged users cannot escalate their access to arbitrary code execution, thereby maintaining the security of the industrial environment.

Sources

Originally found and disclosed by Diego Giubertoni from Nozomi Networks, per the CVE Program record.