ID

VAR-202505-1588


CVE

CVE-2025-26390


TITLE

Siemens'  OZW672  firmware and  OZW772  in the firmware  SQL  Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2025-015585

DESCRIPTION

A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as Administrator user. Siemens' OZW672 firmware and OZW772 The firmware has SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. OZW devices (web servers) are used to remotely monitor building controller devices, for example for monitoring heating controls or air conditioning conditions. Siemens OZW672 and OZW772 web servers have code execution and SQL injection vulnerabilities that can be exploited by an attacker to execute arbitrary code on the device with root privileges (in versions prior to V8.0) or authenticate as an administrator user (in versions prior to V6.0)

Trust: 2.16

sources: NVD: CVE-2025-26390 // JVNDB: JVNDB-2025-015585 // CNVD: CNVD-2025-10580

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-10580

AFFECTED PRODUCTS

vendor:siemensmodel:ozw772scope:ltversion:6.0

Trust: 1.6

vendor:siemensmodel:ozw672scope:ltversion:6.0

Trust: 1.0

vendor:シーメンスmodel:ozw772scope: - version: -

Trust: 0.8

vendor:シーメンスmodel:ozw672scope: - version: -

Trust: 0.8

vendor:siemensmodel:ozw672scope: - version: -

Trust: 0.6

vendor:siemensmodel:ozw772scope:ltversion:8.0

Trust: 0.6

sources: CNVD: CNVD-2025-10580 // JVNDB: JVNDB-2025-015585 // NVD: CVE-2025-26390

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2025-26390
value: CRITICAL

Trust: 1.0

OTHER: JVNDB-2025-015585
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2025-10580
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-10580
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2025-26390
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-015585
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-10580 // JVNDB: JVNDB-2025-015585 // NVD: CVE-2025-26390

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.0

problemtype:SQL injection (CWE-89) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-015585 // NVD: CVE-2025-26390

EXTERNAL IDS

db:NVDid:CVE-2025-26390

Trust: 3.2

db:SIEMENSid:SSA-047424

Trust: 2.4

db:ICS CERTid:ICSA-25-135-10

Trust: 0.8

db:JVNid:JVNVU92528757

Trust: 0.8

db:JVNDBid:JVNDB-2025-015585

Trust: 0.8

db:CNVDid:CNVD-2025-10580

Trust: 0.6

sources: CNVD: CNVD-2025-10580 // JVNDB: JVNDB-2025-015585 // NVD: CVE-2025-26390

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-047424.html

Trust: 2.4

url:https://jvn.jp/vu/jvnvu92528757/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-26390

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-10

Trust: 0.8

sources: CNVD: CNVD-2025-10580 // JVNDB: JVNDB-2025-015585 // NVD: CVE-2025-26390

SOURCES

db:CNVDid:CNVD-2025-10580
db:JVNDBid:JVNDB-2025-015585
db:NVDid:CVE-2025-26390

LAST UPDATE DATE

2025-10-12T22:21:35.824000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-10580date:2025-05-23T00:00:00
db:JVNDBid:JVNDB-2025-015585date:2025-10-09T08:39:00
db:NVDid:CVE-2025-26390date:2025-10-03T20:46:58.210

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-10580date:2025-05-13T00:00:00
db:JVNDBid:JVNDB-2025-015585date:2025-10-09T00:00:00
db:NVDid:CVE-2025-26390date:2025-05-13T10:15:23.703