CVE-2026-14169
ads-tec Industrial IT · DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
A logic error in ads-tec Industrial IT DVG series devices allows low privileged attackers to overwrite user passwords, potentially leading to administrative lockout.
Executive summary
A logic flaw in ads-tec Industrial IT DVG series devices allows a low privileged attacker to overwrite existing user passwords, resulting in a denial of service for administrative functions.
Vulnerability
This vulnerability (CWE-696) involves an incorrect behavior order that allows a low privileged remote attacker to trigger an inconsistent account state. By sending crafted input, an attacker can overwrite existing passwords, rendering the device inaccessible to administrators.
Business impact
The primary impact is the loss of administrative control over critical industrial IT infrastructure. With a CVSS score of 8.1, the ability for a low privileged user to cause a complete denial of service for administrators represents a significant operational risk, potentially requiring physical intervention to restore device access.
Remediation
Immediate Action: Update the firmware of all affected ads-tec Industrial IT DVG devices to version 2.3.0 or higher.
Proactive Monitoring: Audit user account management logs for suspicious modifications or repeated failed authentication attempts that may indicate manipulation.
Compensating Controls: Restrict remote access to the device management interfaces to trusted, authenticated users only via VPN or dedicated management segments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
To maintain system availability and administrative integrity, administrators must apply the vendor provided firmware update. Limiting access to the management interface remains a vital defensive practice to prevent low privileged users from impacting device availability.