CVE-2026-63586

9.8

Weidmueller Interface · IE-SR-2TX-WL

An OS command injection vulnerability in the web management interface of Weidmueller IE-SR-2TX-WL devices allows unauthenticated attackers to execute arbitrary commands with root privileges.

Executive summary

A critical OS command injection vulnerability in Weidmueller IE-SR-2TX-WL devices permits unauthenticated, remote attackers to execute arbitrary code with root-level access.

Vulnerability

The web management interface fails to sanitize input in the HTTP Basic Authentication header, leading to OS command injection (CWE-78) via the system() function. This allows an unauthenticated attacker with network access to the device to run commands as root.

Business impact

Successful exploitation results in total system compromise, granting an attacker full control over the affected industrial networking hardware. With a CVSS score of 9.8, this represents a critical risk to operational technology environments, potentially leading to unauthorized network access or disruption of industrial processes.

Remediation

Immediate Action: Update the firmware of all affected Weidmueller devices to the latest patched version.

Proactive Monitoring: Inspect network traffic for unusual HTTP Basic Authentication headers containing shell metacharacters.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) to filter malicious input strings directed at the device management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The combination of an unauthenticated attack vector and root-level impact necessitates an immediate response. Organizations using these devices must verify their firmware versions and apply the vendor-provided updates as soon as they are made available to prevent remote command execution.

More Weidmueller Interface CVEs