CVE-2025-41753

Summary

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

Affected Software

VendorProductVersion RangeStatus
WAGO0751-9x011.0.0 < 4.8.9affected
WAGO0750-811x-xxxx-xxxx1.0.0 < 4.8.9affected
WAGO0750-821x-xxx-xxx1.0.0 < 4.8.9affected
WAGO0762-420x-8000-000x1.0.0 < 4.8.9affected
WAGO0762-430x-8000-000x1.0.0 < 4.8.9affected
WAGO0762-520x-8000-000x1.0.0 < 4.8.9affected
WAGO0762-530x-8000-000x1.0.0 < 4.8.9affected
WAGO0762-620x-8000-000x1.0.0 < 4.8.9affected
WAGO0762-630x-8000-000x1.0.0 < 4.8.9affected
WAGO0752-8303-8000-00021.0.0 < 4.8.9affected
WAGO0762-340x1.0.0 < 4.8.9affected
WAGO0751-9x011.0.0 < 4.8.9 (70)affected
WAGO0750-811x-xxxx-xxxx1.0.0 < 4.8.9 (70)affected
WAGO0750-821x-xxx-xxx1.0.0 < 4.8.9 (70)affected
WAGO0762-420x-8000-000x1.0.0 < 4.8.9 (70)affected
WAGO0762-430x-8000-000x1.0.0 < 4.8.9 (70)affected
WAGO0762-520x-8000-000x1.0.0 < 4.8.9 (70)affected
WAGO0762-530x-8000-000x1.0.0 < 4.8.9 (70)affected
WAGO0762-620x-8000-000x1.0.0 < 4.8.9 (70)affected
WAGO0762-630x-8000-000x1.0.0 < 4.8.9 (70)affected
WAGO0752-8303-8000-00021.0.0 < 4.8.9 (70)affected
WAGO0762-340x1.0.0 < 4.8.9 (70)affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References