Back to overview

Pepperl+Fuchs: Comtrol RocketLinx ICRL-M - Multiple Vulnerabilities

VDE-2020-053
Last update
05/22/2025 15:03
Published at
03/08/2021 14:44
Vendor(s)
Pepperl+Fuchs SE
External ID
VDE-2020-053
CSAF Document

Summary

Several critical vulnerabilities within firmware.

Impact

Pepperl+Fuchs analyzed and identified affected devices.
Remote attackers may exploit multiple vulnerabilities to get access to the device and execute any program and tap information.

Affected Product(s)

Model no. Product name Affected versions
Hardware ICRL-M-16RJ45/4CP-G-DIN Firmware <=1.3.1
ICRL-M-8RJ45/4SFP-G-DIN Firmware <=1.3.1

Vulnerabilities

Expand / Collapse all

Published
09/02/2026 14:29
Weakness
Hidden Functionality (CWE-912)
Summary

Active TFTP-Service

References

Published
09/02/2026 14:29
Weakness
Cross-Site Request Forgery (CSRF) (CWE-352)
Summary

Unauthenticated Device Administration

References

Published
09/02/2026 14:29
Weakness
Improper Input Validation (CWE-20)
Summary

Multiple Authenticated Command Injections

References

Acknowledgments

Pepperl+Fuchs SE thanks the following parties for their efforts:

  • CERT@VDE for the coordination and support with this publication. (see https://certvde.com )
  • T. Weber from SEC Consult Vulnerability Lab for reported.

Revision History

Version Date Summary
1 03/08/2021 14:44 initial revision
2 02/12/2025 17:48 Fix: corrected self-reference, fixed version
3 05/22/2025 15:03 Fix: reference category, added distribution, quotation mark