CVE-2025-24346
A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to manipulate the “/etc/environment” file via a crafted HTTP request.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.49%
- CWE
- CWE-1286
- Published
- 2025-04-30
- Last modified
- 2026-03-12
Affected products
- Bosch Rexroth AG ctrlX OS - Device Admin
- Bosch Rexroth AG ctrlX OS - Device Admin
- Bosch Rexroth AG ctrlX OS - Device Admin
Weakness type
Related vulnerabilities
- CVE-2026-83611 — xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
- CVE-2026-72916 — Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
- CVE-2026-0931 — Denial-of-service vulnerability in M-Files Server
- CVE-2026-25292 — Improper Validation of Syntactic Correctness of Input in Automotive Linux OS
- CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
- CVE-2026-55767 — Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2025-8873 — Arista EOS Dataplane Denial of Service via Malformed IPsec Packet