CVE-2025-48860: Bosch Rexroth AG Ctrlx OS - Setup

High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to backup archives created by a user with elevated permissions. Depending on the content of the backup archive, the attacker may have been able to access sensitive data.

Affected products

  • Bosch Rexroth AG Ctrlx OS - Setup: from 1.20.0, up to and including 1.20.1; from 2.6.0, up to and including 2.6.1; from 3.6.0, up to and including 3.6.2

Published 2025-08-14. Last modified 2026-06-17.