Weidmueller IE-SR-2TX Routers Cross-Site Request Forgery Vulnerability Allowing Unauthenticated Command Execution

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Main Web Interface of Weidmueller security routers IE-SR-2TX, specifically in the event_mail_test endpoint. This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with root privileges on the affected devices. The issue arises from a lack of CSRF protection, leaving the routers open to exploitation.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected routers with root privileges.

Remediation

Users are advised to update to version 1.49 or 1.62, depending on their current version. Instructions for updating can be found in the Weidmueller advisory VDE-2025-052.

Added: Jun 11, 2025, 9:26 AM
Updated: Jun 11, 2025, 9:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.