CVE-2025-48862: Bosch Rexroth AG Ctrlx OS - Setup

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains unencrypted.

Affected products

  • Bosch Rexroth AG Ctrlx OS - Setup: from 1.20.0, up to and including 1.20.1; from 2.6.0, up to and including 2.6.1; from 3.6.0, up to and including 3.6.2

Published 2025-08-14. Last modified 2026-06-17.