Weidmueller IE-SR-2TX Routers Cross-Site Request Forgery Vulnerability Allowing Arbitrary Command Execution
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Main Web Interface of Weidmueller security routers IE-SR-2TX, specifically in the endpoints related to IoT generation settings. This vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on the affected devices. The issue arises from a lack of proper CSRF protection, enabling exploitation by manipulating user interactions with the web interface.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected routers with root privileges.
Remediation
Users are advised to update to version 1.49 or 1.62, depending on their current version. The specific update version can be found in the Weidmueller advisory.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
