---
id: CVE-2025-13605
title: "3onedata modbus gateway device model\_GW1101-1D(RS-485)-TB-P (hardware version V2.2.0)\_allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the \"IP address\" field of the di…"
summary: "3onedata modbus gateway device model\_GW1101-1D(RS-485)-TB-P (hardware version V2.2.0)\_allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the \"IP address\" field of the di…"
severity: none
cwe:
  - CWE-78
published: '2026-05-04'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13605'
references:
  - url: 'https://cert.pl/en/posts/2026/05/CVE-2025-13605'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00198
epssPercentile: 0.08656
ingestedAt: '2026-09-30T22:27:27.775Z'
---

## Overview

3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test tools.
This issue has been resolved in firmware version 3.0.59B2024080600R4353

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
