Showing 4 vulnerabilities on this page for DVG-IRF1401

Signals CISA KEV Ransomware Nuclei
ads-tec Industrial IT vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ads-tec Industrial IT: Post-login open redirect in the web interface

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

CWE-601Jul 28, 2026
CVSS6.1v3.1EPSS0.183%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ads-tec Industrial IT: Account lockout via non-atomic user creation

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

CWE-696Jul 28, 2026
CVSS8.1v3.1EPSS0.288%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ads-tec Industrial IT: Vertical privilege escalation via configuration table write

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

CWE-862Jul 28, 2026
CVSS8.8v3.1EPSS0.277%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ads-tec Industrial IT: Privilege escalation during configuration import

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

CWE-863Jul 28, 2026
CVSS8.7v4.0EPSS0.277%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX