CVE-2026-14171

Summary

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

Affected Software

VendorProductVersion RangeStatus
ads-tec Industrial ITDVG-IRF14012.2.5 < 2.3.0affected
ads-tec Industrial ITDVG-IRF14212.2.5 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34012.2.5 < 2.3.0affected
ads-tec Industrial ITDVG-IRF34212.2.5 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38012.2.5 < 2.3.0affected
ads-tec Industrial ITDVG-IRF38212.2.5 < 2.3.0affected

Weaknesses

  • CWE-601: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References