Bosch Rexroth ctrlX OS Setup Web Application Backup Access Vulnerability

Vulnerability

A vulnerability exists in the web application of the ctrlX OS setup mechanism, allowing an authenticated (low privileged) attacker to remotely access backup archives created by users with elevated permissions. Depending on the backup's content, this could lead to exposure of sensitive data.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive data contained in backup archives.

Remediation

Users are strongly advised to update to the latest version of the ctrlX OS Setup app. After updating, the device may need to be rebooted, temporarily making it unavailable. To verify the update, check the version using the device's package management. If a backup has been created and downloaded, delete the backup file using the web interface.

Added: Aug 14, 2025, 9:30 AM
Updated: Aug 14, 2025, 9:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.