Weidmueller IE-SR-2TX Routers Cross-Site Request Forgery Vulnerability Allowing Unauthenticated Command Execution
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Main Web Interface of Weidmueller security routers IE-SR-2TX, specifically in the event_mail_test endpoint. This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with root privileges on the affected devices. The issue arises from a lack of CSRF protection, leaving the routers open to exploitation.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected routers with root privileges.
Remediation
Users are advised to update to version 1.49 or 1.62, depending on their current version. Instructions for updating can be found in the Weidmueller advisory VDE-2025-052.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
