Impact
A remote attacker with low privileges can execute a write operation to the device’s configuration table because the insert path lacks proper authorization checks. By exploiting this deficiency the attacker can gain administrator privileges, allowing full control over the device and its protected resources.
Affected Systems
ads‑tec Industrial IT devices DVG‑IRF1401, DVG‑IRF1421, DVG‑IRF3401, DVG‑IRF3421, DVG‑IRF3801, and DVG‑IRF3821 are affected. No specific firmware version information is provided, so all current firmware releases for these models are potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity, while the EPSS score is below 1 %, indicating low but non‑zero exploitation probability. It is not listed in CISA KEV. The attack appears to be remote, requiring only that the attacker can access the device’s management interface to submit a configuration write. No additional conditions are stated, so the flaw could be leveraged by any unauthorized user with network reachability to the target.
OpenCVE Enrichment