CVE-2025-59460 Details
Description
The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.
A vulnerability has been identified in the SICK TLOC100-100 product, all versions, including the firmware version 7.1.1. The vulnerability arises from the system being deployed with default configuration settings that do not align with current best practices for access restriction. This default state increases the risk of unauthorized connections. The issue is compounded by the fact that the device operates on an outdated operating system, which may be vulnerable to known threats.
Users are strongly recommended to upgrade to the latest release of TLOC100-100 (version 7.1.1 or later).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sick tloc100-100 firmware | < 7.1.1 |
CPE
Remediation
| |
| sick tloc100-100 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | Initial Analysis | [email protected] |
| Oct 27, 2025 | New CVE Received | [email protected] |