CVE-2025-41652: Weidmueller Ie-Sw-PL10M-3gt-7tx
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device.
Affected products
- Weidmueller Ie-Sw-PL10M-3gt-7tx: from 0.0.0, before 3.3.34 (fixed in 3.3.34)
- Weidmueller Ie-Sw-PL10MT-3gt-7tx: from 0.0.0, before 3.3.34 (fixed in 3.3.34)
- Weidmueller Ie-Sw-PL16M-16tx: from 0.0.0, before 3.4.32 (fixed in 3.4.32)
- Weidmueller Ie-Sw-PL16MT-16tx: from 0.0.0, before 3.4.32 (fixed in 3.4.32)
- Weidmueller Ie-Sw-PL18M-2gc-16tx: from 0.0.0, before 3.4.40 (fixed in 3.4.40)
- Weidmueller Ie-Sw-PL18MT-2gc-16tx: from 0.0.0, before 3.4.40 (fixed in 3.4.40)
- Weidmueller Ie-Sw-VL05M-5tx: from 0.0.0, before 3.6.32 (fixed in 3.6.32)
- Weidmueller Ie-Sw-VL05MT-5tx: from 0.0.0, before 3.6.32 (fixed in 3.6.32)
- Weidmueller Ie-Sw-VL08MT-5tx-1sc-2scs: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
- Weidmueller Ie-Sw-VL08MT-6tx-2sc: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
- Weidmueller Ie-Sw-VL08MT-6tx-2scs: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
- Weidmueller Ie-Sw-VL08MT-6tx-2st: from 0.0.0, before 3.5.36 (fixed in 3.5.36)
- Weidmueller Ie-Sw-VL08MT-8tx: from 0.0.0, before 3.6.32 (fixed in 3.6.32)
Published 2025-05-27. Last modified 2026-06-17.