CVE-2025-41753
Received Received - Intake

BACnet File Object Path Traversal Vulnerability

Vulnerability report for CVE-2025-41753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CERT VDE

Description

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wago wago_os_linux to 4.8.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper validation of object names when creating BACnet File Objects. The system interprets these names as file paths but fails to restrict them to the intended directory. This allows unauthenticated remote attackers to use relative paths to access or modify files outside the intended directory, potentially leading to full system compromise.

Detection Guidance

To detect this vulnerability, scan your network for devices running WAGO firmware versions below 4.8.9. Use tools like nmap to identify BACnet services on port 47808/udp. Check device firmware versions via web interfaces or SNMP queries. Monitor for unusual file access patterns or unauthorized file modifications.

Impact Analysis

An attacker could read sensitive files like password files or overwrite critical system files, causing service disruption or complete system compromise. This may expose confidential data, disrupt operations, or allow further attacks on the device or network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage due to data breaches or unauthorized file access.

Mitigation Strategies

Immediately update affected WAGO devices to firmware version 4.8.9 (FW30) or higher. If custom firmware is used, contact WAGO support for updates. Isolate vulnerable devices from critical networks until patched. Disable BACnet services if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-41753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart