CVE-2025-13605 - CVE House
Back to Database
Status published Critical CVE-2025-13605

Shell command injection in 3onedata GW1101-1D(RS-485)-TB-P modbus gateway

Vulnerability Description

3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test tools. This issue has been resolved in firmware version 3.0.59B2024080600R4353

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13605

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Jarosław Wawiórko
  • Łukasz Rybak

Affected Vendor

Affected Software

GW1101-1D(RS-485)-TB-P
Vulnerable Versions:
0

Timeline

Official Publish: May 4th, 2026
Last Modified: May 4th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)