Beckhoff Automation Vulnerabilities and Affected Products
Vulnerabilities associated with MDP software package for TwinCAT/BSD.
Products
Clear product- Beckhoff.Device.Manager.XAR3 vulnerabilities
- MDP for Beckhoff RT Linux(R)3 vulnerabilities
- MDP software package for TwinCAT/BSD3 vulnerabilities
- TF2000-HMI-Server1 vulnerability
- TwinCAT OPC UA Server1 vulnerability
- TwinCAT.HMI.Server1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-41728MEDIUM | Beckhoff: Information leak via Beckhoff Device ManagerA low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response. CWE-125Jan 27, 2026 | CVSS5.3v3.1 | EPSS0.309% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41727HIGH | Beckhoff: Performing privileged operations and gaining administrator accessA local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access. CWE-420Jan 27, 2026 | CVSS7.8v3.1 | EPSS0.163% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41726HIGH | Beckhoff: Arbitrary code execution within privileged processesA low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes. CWE-190Jan 27, 2026 | CVSS8.8v3.1 | EPSS0.414% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |