High - CVE-2025-25268 - An unauthenticated adjacent attacker can modify...
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.
Medium - CVE-2025-41665 - An low privileged remote attacker can enforce...
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.
High - CVE-2025-41666 - A low privileged remote attacker with file...
A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been...
High - CVE-2025-41667 - A low privileged remote attacker with file...
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device.
High - CVE-2025-41668 - A low privileged remote attacker with file...
A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device.
Medium - CVE-2025-42956 - SAP NetWeaver Application Server ABAP and ABAP...
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on...