{"id":"CVE-2025-41753","title":"The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation","summary":"The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse ou…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"WAGO","product":"0751-9x01","affected":["0751-9x01 >= 1.0.0 < 4.8.9","0750-811x-xxxx-xxxx >= 1.0.0 < 4.8.9","0750-821x-xxx-xxx >= 1.0.0 < 4.8.9","0762-420x-8000-000x >= 1.0.0 < 4.8.9","0762-430x-8000-000x >= 1.0.0 < 4.8.9","0762-520x-8000-000x >= 1.0.0 < 4.8.9","0762-530x-8000-000x >= 1.0.0 < 4.8.9","0762-620x-8000-000x >= 1.0.0 < 4.8.9","0762-630x-8000-000x >= 1.0.0 < 4.8.9","0752-8303-8000-0002 >= 1.0.0 < 4.8.9","0762-340x >= 1.0.0 < 4.8.9","0751-9x01 >= 1.0.0 < 4.8.9 (70)","0750-811x-xxxx-xxxx >= 1.0.0 < 4.8.9 (70)","0750-821x-xxx-xxx >= 1.0.0 < 4.8.9 (70)","0762-420x-8000-000x >= 1.0.0 < 4.8.9 (70)","0762-430x-8000-000x >= 1.0.0 < 4.8.9 (70)","0762-520x-8000-000x >= 1.0.0 < 4.8.9 (70)","0762-530x-8000-000x >= 1.0.0 < 4.8.9 (70)","0762-620x-8000-000x >= 1.0.0 < 4.8.9 (70)","0762-630x-8000-000x >= 1.0.0 < 4.8.9 (70)","0752-8303-8000-0002 >= 1.0.0 < 4.8.9 (70)","0762-340x >= 1.0.0 < 4.8.9 (70)"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T07:16:32.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-41753","references":[{"url":"https://www.certvde.com/en/advisories/VDE-2025-102/","label":"info@cert.vde.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T07:39:31.464Z","slug":"CVE-2025-41753","body":"## Overview\n\nThe object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}