CVE-2025-41728: Beckhoff Automation Beckhoff.device.manager.xar

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.

Affected products

Published 2026-01-27. Last modified 2026-06-17.