WEIDMUELLER: WLAN devices affected by OS Command Injection vulnerability
Description
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Command injection in Weidmueller industrial WLAN devices allows authenticated low-privilege users to execute arbitrary commands via a crafted iw_serverip parameter.
Vulnerability
A command injection vulnerability exists in the iw_webs functionality of multiple versions of Weidmueller Industrial WLAN devices. The iw_serverip parameter is not properly sanitized, allowing user input to be reflected in a subsequent call to iw_system, a system-level command execution function. This leads to arbitrary command execution on the device. The affected versions are not explicitly enumerated in the available references, but the advisory from CERT VDE (VDE-2026-026) indicates that multiple versions are impacted [1].
Exploitation
An attacker must be authenticated to the device with a low-privilege user account to exploit this vulnerability. The attacker sends a specially crafted iw_serverip parameter, which is then passed unsanitized into a system command. No user interaction beyond the initial authentication is required, and no race condition or other timing-dependent behavior is needed [1].
Impact
Successful exploitation gives the attacker remote control over the device, allowing arbitrary command execution with the privileges of the iw_webs process (typically root or similar high-level access). This results in full compromise of confidentiality, integrity, and availability (CIA) of the device and potentially the wider industrial network it is connected to [1].
Mitigation
The vendor advisory VDE-2026-026 recommends upgrading to a patched firmware version. Specific fixed versions and release dates are not provided in the available references. If no patch is available, isolating affected devices from untrusted networks and restricting authentication access to trusted users are advised workarounds [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Weidmüller/IE-WL(T)-BL-AP-CL-XXv5Range: IE-WL-BL-AP-CL-EU (2536600000)
- Weidmüller/IE-WL(T)-VL-AP-CL-XXv5Range: IE-WL-VL-AP-BR-CL-EU (2536680000)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert.vde.com/en-us/advisories/vde-2021-026mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.