Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14168— ads-tec Industrial IT: Vertical privilege escalation via configuration table write

CVSS 8.8 · High EPSS 0.28% · P20

Affected Version Matrix 6

VendorProductVersion RangeStatus
ads-tec Industrial ITDVG-IRF14011.0.0< 2.3.0affected
ads-tec Industrial ITDVG-IRF14211.0.0< 2.3.0affected
ads-tec Industrial ITDVG-IRF34011.0.0< 2.3.0affected
ads-tec Industrial ITDVG-IRF34211.0.0< 2.3.0affected
ads-tec Industrial ITDVG-IRF38011.0.0< 2.3.0affected
ads-tec Industrial ITDVG-IRF38211.0.0< 2.3.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-14168

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ads-tec Industrial IT: Vertical privilege escalation via configuration table write
Source: CVE Program / CVE List V5
Vulnerability Description
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
ads-tec Industrial IT DVG-IRF1401 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ads-tec Industrial IT DVG-IRF1401是德国ads-tec Industrial IT公司的一款工业路由器。 ads-tec Industrial IT DVG-IRF1401、DVG-IRF1421、DVG-IRF3401、DVG-IRF3421、DVG-IRF3801和DVG-IRF3821 2.3.0之前版本存在授权问题漏洞,该漏洞源于配置表插入路径缺少授权,导致低权限远程攻击者可获得管理员权限,从而完全控制系统。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ads-tec Industrial ITDVG-IRF1401 1.0.0 ~ 2.3.0 -
ads-tec Industrial ITDVG-IRF1421 1.0.0 ~ 2.3.0 -
ads-tec Industrial ITDVG-IRF3401 1.0.0 ~ 2.3.0 -
ads-tec Industrial ITDVG-IRF3421 1.0.0 ~ 2.3.0 -
ads-tec Industrial ITDVG-IRF3801 1.0.0 ~ 2.3.0 -
ads-tec Industrial ITDVG-IRF3821 1.0.0 ~ 2.3.0 -

II. Public POCs for CVE-2026-14168

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14168

登录查看更多情报信息。

Vendor Advisories for CVE-2026-14168 (1)

Same Patch Batch · ads-tec Industrial IT · 2026-07-28 · 4 CVEs total

CVE-2026-141678.8 HIGHads-tec Industrial IT: Privilege escalation during configuration import
CVE-2026-141698.1 HIGHads-tec Industrial IT: Account lockout via non-atomic user creation
CVE-2026-141716.1 MEDIUMads-tec Industrial IT: Post-login open redirect in the web interface

IV. Related Vulnerabilities

V. Comments for CVE-2026-14168

No comments yet


Leave a comment