CVE-2026-14167

ads-tec · DVG-IRF1401

The ads-tec Industrial IT DVG-IRF1401 series is affected by an authorization flaw allowing low-privileged users to perform unauthorized administrative configuration changes.

Executive summary

A critical authorization bypass vulnerability in ads-tec industrial devices allows low-privileged users to escalate privileges and perform unauthorized administrative tasks.

Vulnerability

The device suffers from incorrect authorization (CWE-863), where a low-privileged authenticated user can perform configuration changes reserved for administrators.

Business impact

This vulnerability allows an attacker who has already gained low-level access to the system to take full control of the device. This can result in unauthorized changes to industrial processes, loss of system availability, or complete compromise of the unit. The 8.8 CVSS score reflects the high impact of this unauthorized privilege escalation.

Remediation

Immediate Action: Update affected DVG-IRF series hardware to version 2.3.0 or the latest available firmware provided by the vendor.

Proactive Monitoring: Audit user account activities and configuration change logs for any unauthorized modifications initiated by low-privileged accounts.

Compensating Controls: Limit access to the device management interface to authenticated and authorized personnel only, utilizing network segmentation to isolate industrial control components.

Exploitation status

Public Exploit Available: No confirmed public exploit available.

Analyst recommendation

This vulnerability presents a significant risk to industrial environments. It is imperative to update the affected devices to the patched version as soon as possible to prevent potential privilege escalation and unauthorized system control.