Bosch Rexroth ctrlX OS Proxy Functionality Vulnerability Allowing Unauthorized Manipulation of Environment File

Vulnerability

A vulnerability exists in the Proxy functionality of the web application in Bosch Rexroth ctrlX OS. This issue allows a remote authenticated (low-privileged) attacker to manipulate the '/etc/environment' file by sending a crafted HTTP request. The vulnerability arises from improper validation of input, which could be exploited to alter environment variables on the affected system.

Impact

Exploitation of this vulnerability allows for unauthorized modification of the '/etc/environment' file, potentially leading to arbitrary code execution with elevated privileges, as changes to this file can affect system-wide environment variables.

Remediation

Users are advised to update to the latest versions of the affected components. The update may require a device reboot. To check if the updated versions are installed, use the device's package management system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.