CVE-2025-24347 Details
Description
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration file via a crafted HTTP request.
A vulnerability exists in the Network Interfaces feature of the Bosch ctrlX OS web application. This issue allows remote authenticated (low-privileged) attackers to alter the network configuration file by sending a crafted HTTP request. The vulnerability arises from improper validation of input, enabling unauthorized modifications to network settings.
Users are advised to update to the latest versions of the affected components. The update process may require a device reboot. To check if the update was successful, verify the installed version using the device's package management system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 30, 2025CISA-ADP
Assessed Apr 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.bosch.com/security-advisories/BOSCH-SA-640452.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bosch Rexroth AG ctrlX OS - Device Admin | All versions |
CPE
Remediation
| |
| Bosch Rexroth AG ctrlX OS - Solutions | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2025 | New CVE Received | [email protected] |
Volerion