CVE-2026-14167

Summary

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

Affected Software

VendorProductVersion RangeStatus
ads-tec Industrial ITDVG-IRF14011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF14211.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34211.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38211.0.0 < 2.3.0affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References