8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Description
A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to backup archives created by a user with elevated permissions. Depending on the content of the backup archive, the attacker may have been able to access sensitive data.
Basic Information
ID
CVE-2025-48860
Source
bosch
Published
Aug 14, 2025 at 09:06
Affected Product
Vendor
Bosch Rexroth AG
Product
ctrlX OS - Setup
Version
1.20.0
Affected Versions
Bosch Rexroth AG ctrlX OS - Setup 1.20.0
Bosch Rexroth AG ctrlX OS - Setup 2.6.0
Bosch Rexroth AG ctrlX OS - Setup 3.6.0
Bosch Rexroth AG ctrlX OS - Setup 2.6.0
Bosch Rexroth AG ctrlX OS - Setup 3.6.0