Bosch Rexroth AG Vulnerabilities and Affected Products
Vulnerabilities associated with ctrlX OS - Solutions.
Products
Clear product- ctrlX OS - Device Admin12 vulnerabilities
- ctrlX HMI Web Panel - WR21 (WR2107)3 vulnerabilities
- ctrlX HMI Web Panel - WR21 (WR2110)3 vulnerabilities
- ctrlX HMI Web Panel - WR21 (WR2115)3 vulnerabilities
- ctrlX OS - Setup3 vulnerabilities
- ctrlX OS - Solutions3 vulnerabilities
- IndraDrive FWA-INDRV*-MP*1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-24344MEDIUM | A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the context of another user's browser via a crafted HTTP request. CWE-81Apr 30, 2025 | CVSS6.3v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24343MEDIUM | A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files in arbitrary file system paths via a crafted HTTP request. CWE-23Apr 30, 2025 | CVSS5.4v3.1 | EPSS0.519% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24338HIGH | A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to execute arbitrary client-side code in the context of another user's browser via multiple crafted HTTP requests. CWE-116Apr 30, 2025 | CVSS7.1v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |