CVE-2025-32839
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-32839 is a newly discovered vulnerability in TeleControl Server Basic versions prior to V3.1.2.2. This issue allows authenticated, remote attackers to execute SQL injection attacks against the internally used 'GetGateways' method. By exploiting this vulnerability, attackers can bypass authorization controls, read and write to the application's database, and execute code with "NT AUTHORITY\NetworkService" permissions. Successful attacks require the attacker to have access to port 8000 on a vulnerable system. This vulnerability poses a significant risk to organizations using the affected software and should be addressed promptly by updating to the latest version or implementing appropriate security measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Siemens Telecontrol Server Basic
Affected Vendors
- Siemens