CVE-2026-14169

Summary

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

Affected Software

VendorProductVersion RangeStatus
ads-tec Industrial ITDVG-IRF14011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF14211.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34211.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38011.0.0 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38211.0.0 < 2.3.0affected

Weaknesses

  • CWE-696: CWE-696 Incorrect Behavior Order

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References