CVE-2025-59460

7.5

SICK AG · TLOC100-100

The SICK AG TLOC100-100 device is shipped with default configuration settings that use weak credentials, potentially allowing unauthorized network connections.

Executive summary

The SICK AG TLOC100-100 device is vulnerable to unauthorized access due to the use of weak default credentials, necessitating an immediate firmware update.

Vulnerability

This vulnerability involves the use of weak credentials (CWE-1391) in the default system configuration. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates that an unauthenticated attacker can exploit this condition remotely without user interaction.

Business impact

The reliance on default credentials significantly lowers the barrier to entry for unauthorized actors, potentially leading to unauthorized system access or information disclosure. With a CVSS score of 7.5, this high severity flaw poses a substantial risk to operational integrity, as it allows attackers to gain a foothold in the network environment without requiring specialized exploit code.

Remediation

Immediate Action: Upgrade the firmware of all TLOC100-100 units to version 7.1.1 or later as specified in the vendor security advisory.

Proactive Monitoring: Review network access logs for unusual connection patterns or unauthorized login attempts directed at TLOC100-100 devices.

Compensating Controls: Implement strict network segmentation to isolate industrial devices from public or untrusted networks and utilize firewall rules to restrict access to the device management interfaces.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity of this vulnerability and the ease with which default credential flaws can be weaponized, organizations must prioritize the firmware upgrade process. Ensure that all affected TLOC100-100 units are patched to version 7.1.1 or higher and verify that no default administrative passwords remain in use across the production environment.

Sources