CVE-2025-41727
7.8Beckhoff Automation · Device Manager, MDP software package, MDP for RT Linux
A local low privileged attacker can bypass authentication in the Beckhoff Device Manager user interface to perform administrative operations.
Executive summary
An authentication bypass vulnerability in Beckhoff Automation software allows local, low-privileged users to escalate their privileges to administrator level, posing a critical security risk.
Vulnerability
This is an authentication bypass vulnerability caused by an unprotected alternate channel (CWE-420), which allows a local attacker with low privileges to interact with the Device Manager interface as an administrator.
Business impact
Successful exploitation allows an unauthorized user to gain full administrative control over the affected industrial control systems. This level of access could lead to unauthorized system configuration changes, disruption of operational processes, or the compromise of sensitive data, justifying the high CVSS score of 7.8.
Remediation
Immediate Action: Update the affected Beckhoff software packages to the fixed versions (Device Manager XAR 2.5.3, TwinCAT/BSD MDP 1.7.0.0, or RT Linux MDP 0.0.5) as provided by the vendor advisory.
Proactive Monitoring: Review system access logs for unusual administrative activity or unauthorized attempts to access the Device Manager interface from low-privileged accounts.
Compensating Controls: Restrict local access to the affected devices to only authorized personnel and ensure that the host operating system is hardened to prevent unauthorized local user sessions.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for complete administrative takeover of critical industrial devices, organizations should prioritize patching these components. Please verify that all affected Beckhoff installations are updated to the latest versions to mitigate this local privilege escalation risk.
Sources
Originally found and disclosed by Diego Giubertoni from Nozomi Networks, per the CVE Program record.