CVE-2025-41709: Janitza Umg 96rm-E 230v5222062

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.

Affected products

  • Janitza Umg 96rm-E 230v5222062: from 0.0, up to and including 3.13
  • Janitza Umg 96rm-E 24v5222063: from 0.0, up to and including 3.13
  • Weidmueller Energy Meter 750-230 2540910000: from 0.0, up to and including 3.13
  • Weidmueller Energy Meter 750-24 2540900000: from 0.0, up to and including 3.13

Published 2026-03-10. Last modified 2026-06-17.