Bosch Rexroth ctrlX OS Task API Endpoint Improper Access Control Vulnerability

Vulnerability

A vulnerability exists in the Task API endpoint of the ctrlX OS setup mechanism, allowing remote, unauthenticated attackers to access and extract internal application data. This includes potential debug logs and information about the versions of installed applications.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal application data, including debug logs and details about installed application versions.

Remediation

An updated version of the affected component is available for all long-term supported (LTS) releases. Users are strongly recommended to update to the latest version. The update may require a reboot of the device, temporarily making it unavailable. To verify that the updated version is installed, check the version using the device's package management.

Added: Aug 14, 2025, 9:28 AM
Updated: Aug 14, 2025, 9:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.