CVE-2025-41728: Beckhoff Automation Beckhoff.device.manager.xar
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.
Affected products
- Beckhoff Automation Beckhoff.device.manager.xar: from 0.0.0, before 2.5.3 (fixed in 2.5.3)
- Beckhoff Automation Mdp For Beckhoff Rt Linuxr: from 0.0.0, before 0.0.5 (fixed in 0.0.5)
- Beckhoff Automation Mdp Software Package For Twincat/bsd: from 0.0.0, before 1.7.0.0 (fixed in 1.7.0.0)
Published 2026-01-27. Last modified 2026-06-17.