---
id: CVE-2025-41753
title: >-
  The object name of a dynamically created BACnet File Object is interpreted as
  a file path without sufficient validation
summary: >-
  The object name of a dynamically created BACnet File Object is interpreted as
  a file path without sufficient validation. Because relative paths are not
  limited to the intended directory, an unauthenticated remote attacker can
  traverse ou…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: WAGO
product: 0751-9x01
affected:
  - 0751-9x01 >= 1.0.0 < 4.8.9
  - 0750-811x-xxxx-xxxx >= 1.0.0 < 4.8.9
  - 0750-821x-xxx-xxx >= 1.0.0 < 4.8.9
  - 0762-420x-8000-000x >= 1.0.0 < 4.8.9
  - 0762-430x-8000-000x >= 1.0.0 < 4.8.9
  - 0762-520x-8000-000x >= 1.0.0 < 4.8.9
  - 0762-530x-8000-000x >= 1.0.0 < 4.8.9
  - 0762-620x-8000-000x >= 1.0.0 < 4.8.9
  - 0762-630x-8000-000x >= 1.0.0 < 4.8.9
  - 0752-8303-8000-0002 >= 1.0.0 < 4.8.9
  - 0762-340x >= 1.0.0 < 4.8.9
  - 0751-9x01 >= 1.0.0 < 4.8.9 (70)
  - 0750-811x-xxxx-xxxx >= 1.0.0 < 4.8.9 (70)
  - 0750-821x-xxx-xxx >= 1.0.0 < 4.8.9 (70)
  - 0762-420x-8000-000x >= 1.0.0 < 4.8.9 (70)
  - 0762-430x-8000-000x >= 1.0.0 < 4.8.9 (70)
  - 0762-520x-8000-000x >= 1.0.0 < 4.8.9 (70)
  - 0762-530x-8000-000x >= 1.0.0 < 4.8.9 (70)
  - 0762-620x-8000-000x >= 1.0.0 < 4.8.9 (70)
  - 0762-630x-8000-000x >= 1.0.0 < 4.8.9 (70)
  - 0752-8303-8000-0002 >= 1.0.0 < 4.8.9 (70)
  - 0762-340x >= 1.0.0 < 4.8.9 (70)
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T07:16:32.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-41753'
references:
  - url: 'https://www.certvde.com/en/advisories/VDE-2025-102/'
    label: info@cert.vde.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T07:39:31.464Z'
---

## Overview

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
