CVE-2026-14168

ads-tec · Industrial IT DVG-IRF series

A missing authorization vulnerability in the configuration table insert path of various ads-tec Industrial IT devices allows low-privileged remote attackers to gain administrative system access.

Executive summary

A missing authorization flaw in multiple ads-tec Industrial IT devices enables low-privileged remote attackers to escalate their privileges to administrator, resulting in full system compromise.

Vulnerability

The vulnerability exists due to improper authorization checks within the configuration table insert function. An attacker with low-level privileges can interact with this function to bypass security controls and gain full administrative access to the affected hardware.

Business impact

Successful exploitation results in a complete loss of confidentiality, integrity, and availability of the affected system. Given the CVSS score of 8.8, this vulnerability poses a significant risk to industrial operations, potentially allowing attackers to modify system configurations, disrupt critical processes, or pivot into the internal network.

Remediation

Immediate Action: Update all affected ads-tec Industrial IT devices to version 2.3.0 or later as specified in the vendor advisory.

Proactive Monitoring: Review system access logs for unauthorized configuration modifications or unusual administrative activity originating from low-privileged accounts.

Compensating Controls: Implement strict network segmentation to isolate these industrial devices from untrusted network segments and restrict management access to authorized personnel only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a high-severity risk to operational technology environments. Administrators must prioritize updating the affected firmware to version 2.3.0 immediately to prevent unauthorized administrative takeover of industrial control hardware.