Siemens SIMATIC IoT2050 Advanced Vulnerable to Remote Code Execution via Node-RED
A critical missing authentication vulnerability in Siemens SIMATIC IoT2050 Advanced devices allows unauthenticated remote attackers to execute arbitrary code with maximum privileges.

Siemens has issued a security advisory for its SIMATIC IoT2050 Advanced devices, detailing a critical vulnerability that could allow remote attackers to gain full control of the affected systems. The flaw, identified as CVE-2026-58115, resides within the Node-RED HTTP interface when installed on the device's Industrial OS.
This vulnerability stems from a failure to enforce proper authentication on the Node-RED HTTP interface. Attackers can exploit this by creating malicious flows through the interface, which then allows them to execute arbitrary code on the underlying server with the highest level of privileges. This could lead to a complete compromise of the device and any connected industrial systems.
The affected product is the Siemens SIMATIC IoT2050 Advanced (part number 6ES7647-0BA00-1YA2) running versions prior to V4.3.4.1 of its Industrial OS with Node-RED installed. The vulnerability has a CVSS v3.1 base score of 10, classifying it as CRITICAL, with an attack vector of Network, low complexity, no privileges required, and no user interaction needed.
Siemens has addressed this vulnerability by releasing version V4.3.4.1 of the SIMATIC IoT2050 Advanced software. The company strongly recommends that all users update to this latest version as soon as possible to mitigate the risk of exploitation. Details on the update and its deployment can be found on the Siemens support portal.
While updating is the primary remediation, Siemens also suggests hardening the Node-RED installation as a mitigation strategy if an immediate update is not feasible. Alternatively, uninstalling Node-RED entirely would also remove the attack surface associated with this specific vulnerability. Further guidance on hardening Node-RED can be found in its official user documentation.
The vulnerability was reported to CISA by Siemens ProductCERT. CISA has highlighted that this issue affects critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Transportation Systems, with devices deployed worldwide. The potential for unauthenticated remote code execution with maximum privileges poses a significant risk to operational technology environments.
As a general security measure, Siemens advises protecting network access to all industrial control system devices using appropriate security mechanisms. Organizations are encouraged to follow Siemens' operational guidelines for Industrial Security and the recommendations provided in product manuals to maintain a secure operating environment. This includes segmenting networks and limiting external access to critical systems.
CISA echoes these recommendations, urging organizations to minimize network exposure for control system devices and ensure they are not accessible from the internet. Implementing firewalls, isolating control system networks from business networks, and using secure remote access methods like VPNs are crucial steps. Organizations should conduct thorough impact and risk assessments before deploying any defensive measures.