Bosch ctrlX OS Username Enumeration Vulnerability

Vulnerability

A vulnerability exists in the login functionality of the ctrlX OS web application, allowing remote unauthenticated attackers to enumerate valid usernames by sending multiple crafted HTTP requests. This issue affects several versions of the ctrlX OS web application, including those in the Device Admin and Solutions components.

Impact

Exploitation of this vulnerability allows for username enumeration, which could facilitate further attacks such as password guessing or phishing.

Remediation

Users are advised to update to the latest versions of the affected applications. The update may require a device reboot. To check if the updated versions are installed, use the device's package management system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.