Summary
The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for the LNI 4.0 testbed demonstrator. Its REST API is bound to all network interfaces on TCP port 18000, requires no authentication and accepts cross-origin requests from any origin. The reference implementation was never intended for productive use and is no longer maintained. Affected are all aas-edge-client versions.
Impact
An unauthenticated remote attacker, or a malicious web page opened by a user on a network that can reach the device, can read and modify the Asset Administration Shell submodel data of the edge device. Modified data is stored locally and forwarded to the configured central AAS server, so systems consuming that server may receive manipulated device information.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| Murrelektronik Software AAS Edge Client all versions | vers:all/* |
Vulnerabilities
Expand / Collapse allAn unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
Mitigation
Discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image. The code must not be used in any environment.
Remediation
Murrelektronik GmbH will not provide a fix. The aas-edge-client was a reference implementation created solely for a trade-fair demonstrator and is no longer maintained. All repositories of the Murrelektronik GmbH GitHub organisation have been set to private, and the aas-edge-client repository has additionally been archived.
Acknowledgments
Murrelektronik GmbH thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- kta1kri from for finding and reporting
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 10/06/2026 12:00 | initial release |