Bosch Rexroth ctrlX OS Web Application Arbitrary HTML Injection Vulnerability

Vulnerability

A vulnerability exists in the error notification messages of the ctrlX OS web application, allowing remote unauthenticated attackers to inject arbitrary HTML tags. This injection could potentially be used to execute client-side code in the context of another user's browser, via a crafted HTTP request.

Impact

Exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing for the execution of arbitrary client-side scripts in the affected user's browser.

Remediation

Users are advised to update to the latest versions of the affected applications. The update may require a device reboot. To check if the updated versions are installed, use the device's package management system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.