# CVE-2025-59460

## Summary

- **CVE ID:** CVE-2025-59460
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-1391
- **Published:** Oct 27, 2025
- **Last Modified:** Mar 13, 2026

## Description

The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.

## Affected Products

- SICK AG — TLOC100-100 with Firmware <7.1.1 (0)
- SICK AG — TLOC100-100 with Firmware >=7.1.1 (>=7.1.1)

## References

- [CNA](https://sick.com/psirt)
- [CNA](https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf)
- [CNA](https://www.cisa.gov/resources-tools/resources/ics-recommended-practices)
- [CNA](https://www.first.org/cvss/calculator/3.1)
- [CNA](https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0013.json)
- [CNA](https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0013.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._