ads-tec Industrial IT Vulnerabilities and Affected Products
Vulnerabilities associated with DVG-IRF3821.
Products
Clear product- DVG-IRF14014 vulnerabilities
- DVG-IRF14214 vulnerabilities
- DVG-IRF34014 vulnerabilities
- DVG-IRF34214 vulnerabilities
- DVG-IRF38014 vulnerabilities
- DVG-IRF38214 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-14171MEDIUM | ads-tec Industrial IT: Post-login open redirect in the web interfaceAn unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability. CWE-601Jul 28, 2026 | CVSS6.1v3.1 | EPSS0.183% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14169HIGH | ads-tec Industrial IT: Account lockout via non-atomic user creationDue to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device. CWE-696Jul 28, 2026 | CVSS8.1v3.1 | EPSS0.288% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14168HIGH | ads-tec Industrial IT: Vertical privilege escalation via configuration table writeA low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access. CWE-862Jul 28, 2026 | CVSS8.8v3.1 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14167HIGH | ads-tec Industrial IT: Privilege escalation during configuration importA low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization. CWE-863Jul 28, 2026 | CVSS8.7v4.0 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |