← Back to browse · API

CVE-2026-58115

Severity
CRITICAL
CVSS
10.0
EPSS
0.00654
Risk score
40.23
CISA KEV
No
PoC
No
Published
2026-08-11
Modified
2026-08-12
First seen
2026-08-11
Aliases
EUVD-2026-56119, GHSA-MMH6-F99Q-64FH
Products
Siemens:SIMATIC IoT2050 Advanced 0 <V4.3.4.1
Sources
euvd EUVD-2026-56119
nvd CVE-2026-58115

Description

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.

References