CVE-2025-41651: Weidmueller Ie-Sw-PL10M-3gt-7tx

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.

Affected products

  • Weidmueller Ie-Sw-PL10M-3gt-7tx: from 0.0.0, before 3.3.34 (fixed in 3.3.34)
  • Weidmueller Ie-Sw-PL10MT-3gt-7tx: from 0.0.0, before 3.3.34 (fixed in 3.3.34)
  • Weidmueller Ie-Sw-PL16M-16tx: from 0.0.0, before 3.4.32 (fixed in 3.4.32)
  • Weidmueller Ie-Sw-PL16MT-16tx: from 0.0.0, before 3.4.32 (fixed in 3.4.32)
  • Weidmueller Ie-Sw-PL18M-2gc-16tx: from 0.0.0, before 3.4.40 (fixed in 3.4.40)
  • Weidmueller Ie-Sw-PL18MT-2gc-16tx: from 0.0.0, before 3.4.40 (fixed in 3.4.40)
  • Weidmueller Ie-Sw-VL05M-5tx: from 0.0.0, before 3.6.32 (fixed in 3.6.32)
  • Weidmueller Ie-Sw-VL05MT-5tx: from 0.0.0, before 3.6.32 (fixed in 3.6.32)
  • Weidmueller Ie-Sw-VL08MT-5tx-1sc-2scs: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
  • Weidmueller Ie-Sw-VL08MT-6tx-2sc: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
  • Weidmueller Ie-Sw-VL08MT-6tx-2scs: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
  • Weidmueller Ie-Sw-VL08MT-6tx-2st: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
  • Weidmueller Ie-Sw-VL08MT-8tx: from 0.0.0, before 3.5.36 (fixed in 3.5.36)

Published 2025-05-27. Last modified 2026-06-17.