Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-26390


A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as Administrator user.


Published

2025-05-13T10:15:23.703

Last Modified

2025-10-03T20:46:58.210

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens ozw672_firmware < 6.0 Yes
Hardware siemens ozw672 - No
Operating System siemens ozw772_firmware < 6.0 Yes
Hardware siemens ozw772 - No

References