Back to overview

CVE-2026-14169

HIGH
8.1
CVSS 3.1
Description
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

Metadata

CVE ID
CVE-2026-14169
State
PUBLISHED
Assigner
CERTVDE
Reserved
2026-06-30 06:39 UTC
Published
2026-07-28 09:07 UTC
Last updated
2026-07-28 13:59 UTC
Primary CWE
CWE-696
CWE-696 Incorrect Behavior Order
Vendor / Product
ads-tec Industrial IT / DVG-IRF1401
Sources
cve.org  ·  NVD

Severity & Metrics

8.1 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (6)
VendorProductPlatformVersions
ads-tec Industrial IT DVG-IRF1401 1.0.0 < 2.3.0
ads-tec Industrial IT DVG-IRF1421 1.0.0 < 2.3.0
ads-tec Industrial IT DVG-IRF3401 1.0.0 < 2.3.0
ads-tec Industrial IT DVG-IRF3421 1.0.0 < 2.3.0
ads-tec Industrial IT DVG-IRF3801 1.0.0 < 2.3.0
ads-tec Industrial IT DVG-IRF3821 1.0.0 < 2.3.0
Weakness (CWE)
CWESourceDescription
CWE-696 cna CWE-696 Incorrect Behavior Order
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.1 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Back to overview