Weidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting Endpoint
Vulnerability Description
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41684
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Reid Wightman of Dragos Inc.
More from Weidmueller
View All →Affected Vendor
Weidmueller
View all reports →