CVE-2025-40937High· 8.3▾ TwilightA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow an authenticated attacker to execute arbitrary code with limited privileges.
simatic_cn_4100_firmware < 4.0.1Upgrade past the affected range:
simatic_cn_4100_firmware 4.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-40939Medium· 4.6A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40940Medium· 4.9A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40941Medium· 4.3A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-40938High· 8.1A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1)
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-14707Critical· 9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25