Remote Code Execution Vulnerability in Modbus TCP Communication for Industrial Automation Systems
CVE-2025-48466
Key Information:
- Vendor
Advantech
- Vendor
- CVE Published:
- 24 June 2025
Badges
What is CVE-2025-48466?
CVE-2025-48466 is a critical vulnerability found in Modbus TCP communication used in industrial automation systems, specifically attributed to Advantech's products. This vulnerability allows an unauthenticated remote attacker to send specially crafted Modbus TCP packets. By exploiting this flaw, attackers can manipulate Digital Outputs, potentially gaining unauthorized control over relay channels used in various industrial applications. Such manipulation could lead to severe operational disruptions and safety hazards, given the critical roles these systems play in controlling industrial processes and machinery.
Potential impact of CVE-2025-48466
-
Operational Disruption: Exploitation of this vulnerability can lead to unauthorized manipulation of industrial equipment, causing operational downtime or failure, which can severely impact production schedules and operational efficiency.
-
Safety Risks: Given the nature of industrial automation systems, unauthorized control over relay outputs could compromise safety protocols, potentially leading to catastrophic failures, injuries, or damage to infrastructure.
-
Remote Access Threats: Since the vulnerability allows for unauthenticated access, it increases the risk of attackers gaining a foothold in critical infrastructures, which may facilitate further exploit attempts or allow for lateral movement within networks.
Affected Version(s)
Advantech Wireless Sensing and Equipment (WISE) A2.01 B00
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
References
CVSS V3.1
Timeline
- 📰
First article discovered by Cyber Security Agency of Singapore
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability Reserved