Command Execution Vulnerability in 3onedata Modbus Gateway Device
CVE-2025-13605

9.3CRITICAL

Key Information:

Vendor

3onedata

Vendor
CVE Published:
4 May 2026

What is CVE-2025-13605?

The 3onedata Modbus Gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) is susceptible to a command execution vulnerability. This allows authenticated users to execute arbitrary shell commands with root privileges by supplying a specially crafted payload in the 'IP address' field of the diagnosis test tools. Users are advised to upgrade to firmware version 3.0.59B2024080600R4353 to address this issue and enhance the security of their devices.

Affected Version(s)

GW1101-1D(RS-485)-TB-P 0 < 3.0.59B2024080600R4353

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jarosław Wawiórko
Łukasz Rybak
.