CVE-2026-58115

10.0

Siemens · SIMATIC IoT2050 Advanced

A missing authentication vulnerability in the Node-RED interface of Siemens SIMATIC IoT2050 Advanced devices allows unauthenticated remote attackers to execute arbitrary system commands.

Executive summary

Siemens SIMATIC IoT2050 Advanced devices are vulnerable to unauthenticated remote code execution via a misconfigured Node-RED interface, necessitating immediate configuration changes or patching.

Vulnerability

The device fails to enforce authentication on the Node-RED HTTP interface (CWE-306), allowing an unauthenticated attacker to inject malicious flows and execute commands on the underlying server.

Business impact

A successful attack results in full administrative control over the IoT gateway, facilitating data theft, persistent backdoors, or the disruption of connected industrial processes. With a CVSS score of 10.0, this represents a maximum-severity risk that could lead to the complete compromise of the device and its role in the network.

Remediation

Immediate Action: Update the Siemens SIMATIC IoT2050 Advanced device to firmware version V4.3.4.1 or later.

Proactive Monitoring: Review access logs for the Node-RED web interface and monitor for suspicious command-line activity emanating from the device.

Compensating Controls: Restrict HTTP access to the Node-RED interface using local firewall rules or by placing the device behind a VPN for all management access.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability demands urgent attention due to the ease of exploitation and the depth of access granted to an attacker. Administrators must apply the vendor-provided firmware update immediately and ensure the device is not accessible from untrusted networks.

More Siemens CVEs