Weidmueller IE-SR-2TX Routers Cross-Site Request Forgery Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Main Web Interface of Weidmueller security routers IE-SR-2TX, specifically in the endpoints related to IoT generation settings. This vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on the affected devices. The issue arises from a lack of proper CSRF protection, enabling exploitation by manipulating user interactions with the web interface.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected routers with root privileges.

Remediation

Users are advised to update to version 1.49 or 1.62, depending on their current version. The specific update version can be found in the Weidmueller advisory.

Added: Jun 11, 2025, 9:24 AM
Updated: Jun 11, 2025, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.