CVE-2025-32859

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 89

Summary

CVE-2025-32859 is a newly discovered vulnerability that affects TeleControl Server Basic versions prior to V3.1.2.2. The issue lies in the 'LockWebServerGatewaySettings' method, which is internally used and vulnerable to SQL injection attacks. An authenticated remote attacker can exploit this flaw to bypass authorization controls, access the application's database, and execute code with the permissions of "NT AUTHORITY\\NetworkService." Successful attacks require the attacker to have access to port 8000 on a vulnerable system. This vulnerability poses a significant risk to organizations using the affected version of TeleControl Server Basic and highlights the importance of keeping software up-to-date to mitigate potential cyber threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Siemens Telecontrol Server Basic

Affected Vendors

  • Siemens