CVE-2024-10025: Sick RFU620-10507 Firmware

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.

Affected products

  • Sick RFU620-10507 Firmware: any version
  • Sick AG Sick CLV6XX: any version
  • Sick AG Sick LECTOR6XX: any version
  • Sick AG Sick RFX6XX: any version

Published 2024-10-17. Last modified 2026-06-17.