Description
An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.
Published: 2026-07-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can use the web interface’s post‑login redirect feature that lacks proper validation to send authenticated users to a malicious site. The flaw is a classic open‑redirect (CWE‑601) and can be exploited to trick users into visiting phishing or malware‑laden URLs, potentially leading to loss of confidentiality and availability of the user’s session or data. The description does not state that an attacker can gain direct system access, but because the attack is performed after authentication, it can be used as a foothold for social engineering or credential harvesting.

Affected Systems

The vulnerability affects ad‑s‌tec Industrial IT devices with firmware versions that contain the web UI component, specifically the DVG‑IRF1401, DVG‑IRF1421, DVG‑IRF3401, DVG‑IRF3421, DVG‑IRF3801, and DVG‑IRF3821 product lines. Exact firmware revisions are not listed, so all current releases of these models are potentially affected.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate impact, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation at the time of analysis. The flaw is not listed in CISA KEV, meaning no known widespread exploitation has been reported. The likely attack vector is the public web interface after an attacker has logged in or tricks a legitimate user into authenticating, after which the unvalidated redirect is used. To exploit the flaw the attacker only needs access to the vulnerable web UI, which may be reachable over the local network or exposed to the internet, depending on how the device is deployed.

Generated by OpenCVE AI on August 3, 2026 at 15:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware or corrective package from ad‑s‌tec Industrial IT – reference the vendor’s advisory for update instructions
  • Configure the web UI’s redirect handling (or place a rule on the device) to allow redirects only to trusted internal URLs; remove or disable the generic post‑login redirect feature if possible
  • Deploy network‑level filtering (DNS or proxy) to block or quarantine known malicious domains that could be used as redirect targets
  • Enable logging of redirect attempts and monitor logs for anomalous usage patterns related to post‑login redirects

Generated by OpenCVE AI on August 3, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Ads-tec Industrial It
Ads-tec Industrial It dvg-irf1401
Ads-tec Industrial It dvg-irf1421
Ads-tec Industrial It dvg-irf3401
Ads-tec Industrial It dvg-irf3421
Ads-tec Industrial It dvg-irf3801
Ads-tec Industrial It dvg-irf3821
Vendors & Products Ads-tec Industrial It
Ads-tec Industrial It dvg-irf1401
Ads-tec Industrial It dvg-irf1421
Ads-tec Industrial It dvg-irf3401
Ads-tec Industrial It dvg-irf3421
Ads-tec Industrial It dvg-irf3801
Ads-tec Industrial It dvg-irf3821

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.
Title ads-tec Industrial IT: Post-login open redirect in the web interface
First Time appeared Ads Tec
Ads Tec irf1000 Firmware
Ads Tec irf3000 Firmware
Weaknesses CWE-601
CPEs cpe:2.3:o:ads_tec:irf1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ads_tec:irf3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ads Tec
Ads Tec irf1000 Firmware
Ads Tec irf3000 Firmware
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ads-tec Industrial It Dvg-irf1401 Dvg-irf1421 Dvg-irf3401 Dvg-irf3421 Dvg-irf3801 Dvg-irf3821
Ads Tec Irf1000 Firmware Irf3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-28T15:19:52.672Z

Reserved: 2026-06-30T06:39:09.811Z

Link: CVE-2026-14171

cve-icon Vulnrichment

Updated: 2026-07-28T15:19:17.631Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T09:16:41.840

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-14171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')