Unauthorized File Access Vulnerability in BACnet Devices
CVE-2025-41753

9.3CRITICAL

Key Information:

Vendor

Wago

Vendor
CVE Published:
1 October 2026

What is CVE-2025-41753?

This vulnerability arises from inadequate validation of dynamically created BACnet File Object names, allowing an unauthenticated remote attacker to exploit this weakness. The attacker is able to manipulate file paths, resulting in the potential for unauthorized access to arbitrary files outside the intended directory. This misconfiguration may lead to the reading or overwriting of sensitive files, leaving systems vulnerable and ultimately enabling full compromise of affected devices.

Affected Version(s)

0750-811x-xxxx-xxxx 1.0.0 < 4.8.9

0750-811x-xxxx-xxxx 1.0.0 < 4.8.9 (70)

0750-821x-xxx-xxx 1.0.0 < 4.8.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.