The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-083/ |
|
History
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges. | |
| Title | Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface | |
| First Time appeared |
Weidmueller
Weidmueller fwr Ie Sr 2tx Wl Weidmueller fwr Ie Sr 2tx Wl 4g Eu Us |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:weidmueller:fwr_ie_sr_2tx_wl:*:*:*:*:*:*:*:* cpe:2.3:o:weidmueller:fwr_ie_sr_2tx_wl_4g_eu_us:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Weidmueller
Weidmueller fwr Ie Sr 2tx Wl Weidmueller fwr Ie Sr 2tx Wl 4g Eu Us |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-25T08:54:55.934Z
Reserved: 2026-07-17T06:47:50.712Z
Link: CVE-2026-63586
No data.
Status : Received
Published: 2026-08-25T09:17:31.823
Modified: 2026-08-25T09:17:31.823
Link: CVE-2026-63586
No data.
OpenCVE Enrichment
Updated: 2026-08-25T11:00:13Z
Weaknesses