CVE-2025-32839

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 89

Summary

CVE-2025-32839 is a newly discovered vulnerability in TeleControl Server Basic versions prior to V3.1.2.2. This issue allows authenticated, remote attackers to execute SQL injection attacks against the internally used 'GetGateways' method. By exploiting this vulnerability, attackers can bypass authorization controls, read and write to the application's database, and execute code with "NT AUTHORITY\NetworkService" permissions. Successful attacks require the attacker to have access to port 8000 on a vulnerable system. This vulnerability poses a significant risk to organizations using the affected software and should be addressed promptly by updating to the latest version or implementing appropriate security measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Siemens Telecontrol Server Basic

Affected Vendors

  • Siemens