Description
An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
0.0 (custom)
0.0 (custom)
0.0 (custom)
0.0 (custom)
Credits
Deutsche Telekom Security (DT Security)
References
certvde.com/en/advisories/VDE-2025-079/
certvde.com/en/advisories/VDE-2025-096/
janitza.csaf-tp.certvde.com/.../white/2026/vde-2025-079.json
weidmueller.csaf-tp.certvde.com/...te/2026/vde-2025-096.json