CVE-2026-14168

Summary

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

Affected Software

VendorProductVersion RangeStatus
ads-tec Industrial ITDVG-IRF14011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF14211.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34211.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38211.0.0 < 2.3.0affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References