CVE-2025-41727 Details
Description
A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.
A vulnerability exists in the Beckhoff Device Manager user interface, allowing local users with low privileges to bypass authentication. This exploitation enables them to perform privileged operations and gain administrator access on Beckhoff IPC or CX devices.
Users are advised to update to version 2.5.3 of the Beckhoff Device Manager XAR tcpkg package or to version 2.5.3 of the Beckhoff IPC Diagnostics software for Windows. For TwinCAT/BSD, the MDP software package should be updated to version 1.7.0.0. Beckhoff RT Linux users should update the mdp-bhf software package to version 0.0.5-1. The MDP.dll library for Windows CE 6.0 and Embedded Compact 7 on x86 and ARM32 should also be updated to version 1.7.0.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 27, 2026CISA-ADP
Assessed Jan 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/de/advisories/VDE-2025-092 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-420 | Unprotected Alternate Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beckhoff Device Manager | All versions |
CPE
Remediation
| |
| Beckhoff MDP | < 1.7.0.0 |
CPE
Remediation
| |
| Beckhoff mdp-bhf | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2026 | New CVE Received | [email protected] |
Volerion