CVE-2025-41726

HIGH

Device Manager - RCE

Title source: llm
STIX 2.1

Description

A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes.

Scores

CVSS v3 8.8
EPSS 0.0027
EPSS Percentile 50.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-190
Status published
Products (3)
Beckhoff Automation/Beckhoff.Device.Manager.XAR 0.0.0 - 2.5.3
Beckhoff Automation/MDP for Beckhoff RT Linux(R) 0.0.0 - 0.0.5
Beckhoff Automation/MDP software package for TwinCAT/BSD 0.0.0 - 1.7.0.0
Published Jan 27, 2026
Tracked Since Feb 18, 2026