CVE-2025-32859
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-32859 is a newly discovered vulnerability that affects TeleControl Server Basic versions prior to V3.1.2.2. The issue lies in the 'LockWebServerGatewaySettings' method, which is internally used and vulnerable to SQL injection attacks. An authenticated remote attacker can exploit this flaw to bypass authorization controls, access the application's database, and execute code with the permissions of "NT AUTHORITY\\NetworkService." Successful attacks require the attacker to have access to port 8000 on a vulnerable system. This vulnerability poses a significant risk to organizations using the affected version of TeleControl Server Basic and highlights the importance of keeping software up-to-date to mitigate potential cyber threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Siemens Telecontrol Server Basic
Affected Vendors
- Siemens