certvde.com
https://certvde.com/de/advisories/VDE-2025-092 CVE-2025-41727
HIGH
Beckhoff: Performing privileged operations and gaining administrator access
Record summary
CVE-2025-41727 has a selected CVSS score of 7.8 (high).
Description
A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Beckhoff.Device.Manager.XARBrowse Beckhoff Automation / Beckhoff.Device.Manager.XARDefault status: unaffected | CVE List | 0.0.0 to < 2.5.3 | affected |
MDP for Beckhoff RT Linux(R)Browse Beckhoff Automation / MDP for Beckhoff RT Linux(R)Default status: unaffected | CVE List | 0.0.0 to < 0.0.5 | affected |
MDP software package for TwinCAT/BSDBrowse Beckhoff Automation / MDP software package for TwinCAT/BSDDefault status: unaffected | CVE List | 0.0.0 to < 1.7.0.0 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-41727