CVE-2025-48860

8.0

Bosch Rexroth AG · ctrlX OS

A broken access control vulnerability in the Bosch Rexroth ctrlX OS setup mechanism allows low privileged authenticated users to access backup archives containing potentially sensitive data.

Executive summary

A high-severity access control vulnerability in Bosch Rexroth ctrlX OS allows authenticated attackers to gain unauthorized access to sensitive backup archives.

Vulnerability

This vulnerability is caused by improper access control (CWE-284) within the web application setup mechanism, permitting a low privileged authenticated attacker to retrieve backup archives generated by users with elevated administrative permissions.

Business impact

The compromise of backup archives poses a significant risk to organizational confidentiality and integrity, as these files often contain sensitive configuration data, credentials, and system state information. With a CVSS score of 8.0, this vulnerability is classified as High, reflecting the potential for severe data exposure and subsequent lateral movement or system disruption if the backup contents are misused.

Remediation

Immediate Action: Update the affected ctrlX OS installations to the versions provided in the official Bosch Rexroth security advisory (BOSCH-SA-129652).

Proactive Monitoring: Review system access logs for unusual patterns of file retrieval or access requests directed at the setup mechanism or backup storage directories.

Compensating Controls: Restrict access to the web interface to authorized internal networks and ensure that only trusted users are granted authentication credentials to the system.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high impact of unauthorized access to backup archives, organizations should prioritize patching affected Bosch Rexroth ctrlX OS instances. Administrators must verify their current firmware or software versions against the affected list and apply the vendor provided updates immediately to prevent potential data exfiltration.

More Bosch Rexroth AG CVEs

Sources