Unauthenticated Access Issue in SIMATIC IoT2050 Advanced by Siemens
CVE-2026-58115
10CRITICAL
What is CVE-2026-58115?
A significant security vulnerability exists within the SIMATIC IoT2050 Advanced device, where the Node-RED HTTP interface does not enforce proper authentication. This oversight permits unauthorized users to access programming nodes and execute system commands on the server. As a result, an attacker could manipulate these capabilities to create malicious flows that execute arbitrary code with elevated privileges, potentially compromising the entire system's integrity.
Affected Version(s)
SIMATIC IoT2050 Advanced 0