CVE-2025-60035

7.8

Bosch Rexroth · IndraWorks

A deserialization vulnerability in the OPC.Testclient utility within Bosch Rexroth IndraWorks allows attackers to achieve remote code execution via a specially crafted file.

Executive summary

A critical deserialization flaw in Bosch Rexroth IndraWorks enables remote code execution if a user opens a malicious file, resulting in full system compromise.

Vulnerability

The vulnerability is a deserialization of untrusted data (CWE-502) within the OPC.Testclient utility. An unauthenticated attacker can achieve remote code execution when a local user is tricked into opening a specially crafted file that triggers the malicious deserialization process.

Business impact

The successful exploitation of this vulnerability leads to a complete compromise of the host system, granting an attacker full control over the affected environment. Given the high CVSS score of 7.8, this poses a significant risk to operational integrity, potentially leading to unauthorized data access, system disruption, and loss of control over industrial automation components managed by the software.

Remediation

Immediate Action: Update Bosch Rexroth IndraWorks to version 15V24 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system logs for unusual process execution patterns initiated by the OPC.Testclient utility and monitor for the opening of unexpected or unrecognized file types.

Compensating Controls: Implement endpoint protection software to scan incoming files for malicious payloads and restrict user permissions to limit the impact of code execution if a system is compromised.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The reliance on user interaction does not diminish the severity of this flaw, as phishing or social engineering can easily facilitate the delivery of the malicious file. Organizations must prioritize upgrading to version 15V24 immediately to remediate the underlying deserialization issue and prevent potential remote code execution attacks against their infrastructure.

More Bosch Rexroth CVEs

Sources