CVE-2025-41731
7.4Jumo · variTRON300, variTRON500, variTRON500 touch
A weak pseudo-random number generator in the Jumo variTRON debug interface allows unauthenticated local attackers to brute force credentials and gain root access.
Executive summary
A critical vulnerability in the Jumo variTRON series password generation algorithm enables unauthenticated local attackers to potentially achieve root-level system compromise.
Vulnerability
This vulnerability involves the use of a cryptographically weak pseudo-random number generator (CWE-338) within the device debug interface. An unauthenticated local attacker who can determine the password generation timeframe may successfully brute force the credentials to obtain root access.
Business impact
The exploitation of this vulnerability could lead to a complete loss of confidentiality, integrity, and availability of the affected industrial control devices. With a CVSS score of 7.4, the risk is high, particularly for environments where unauthorized root access could lead to process disruption, physical safety hazards, or the compromise of sensitive operational data.
Remediation
Immediate Action: Update all affected Jumo variTRON devices to firmware version 9.0.2.5 or later. If an update is not immediately feasible, ensure the debug interface is physically or logically disabled.
Proactive Monitoring: Review device access logs for frequent or failed authentication attempts, especially those originating from unauthorized local connections.
Compensating Controls: Restrict physical access to the devices and ensure that network segments containing industrial controllers are isolated from untrusted traffic to prevent local access attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for full root-level compromise, organizations utilizing Jumo variTRON systems must prioritize patching to version 9.0.2.5. If patching cannot be performed immediately, disabling the debug interface is an essential step to eliminate the attack vector and secure the device against potential brute force attempts.