Back to Database
Status published
Critical
CVE-2025-41651
Weidmueller: Missing Authentication Vulnerability in Industrial Ethernet Switches
Vulnerability Description
Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41651
Credits & Attribution
No credits recorded in the NVD database.
More from Weidmueller
View All →CVE-2025-41687
Weidmueller: Unauthenticated Stack-Based Buffer Overflow in u-link Management API
Critical
9.8
CVE-2025-41684
Weidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting Endpoint
High
8.8
CVE-2025-41683
Weidmueller: Root Command Injection via Unsanitized Input in event_mail_test Endpoint
High
8.8
CVE-2025-41663
Weidmueller: Security routers IE-SR-2TX are affected by Command Injection
Critical
9.8
CVE-2025-41661
Weidmueller: Security routers IE-SR-2TX are affected by CSRF
High
8.8
Affected Vendor
Weidmueller
View all reports →Affected Software
IE-SW-VL05M-5TX, IE-SW-VL05MT-5TX, IE-SW-VL08MT-8TX, IE-SW-VL08MT-5TX-1SC-2SCS, IE-SW-VL08MT-6TX-2SC, IE-SW-VL08MT-6TX-2ST, IE-SW-VL08MT-6TX-2SCS, IE-SW-PL10M-3GT-7TX, IE-SW-PL10MT-3GT-7TX, IE-SW-PL16M-16TX, IE-SW-PL16MT-16TX, IE-SW-PL18M-2GC-16TX, IE-SW-PL18MT-2GC-16TX
Vulnerable Versions:
0.0.0
Timeline
Official Publish:
May 27th, 2025
Last Modified:
May 27th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H