{"api_version":"1","generated_at":"2026-10-02T00:11:53+00:00","cve":"CVE-2025-41753","urls":{"html":"https://cve.report/CVE-2025-41753","api":"https://cve.report/api/cve/CVE-2025-41753.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-41753","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-41753"},"summary":{"title":"Path traversal in dynamically created BACnet File Objects","description":"The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.","state":"PUBLISHED","assigner":"CERTVDE","published_at":"2026-10-01 07:16:32","updated_at":"2026-10-01 20:17:20"},"problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[{"version":"4.0","source":"info@cert.vde.com","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"9.3","severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"info@cert.vde.com","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.certvde.com/en/advisories/VDE-2025-102/","name":"https://www.certvde.com/en/advisories/VDE-2025-102/","refsource":"info@cert.vde.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-41753","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-41753","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"WAGO","product":"0751-9x01","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0750-811x-xxxx-xxxx","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0750-821x-xxx-xxx","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-420x-8000-000x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-430x-8000-000x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-520x-8000-000x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-530x-8000-000x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-620x-8000-000x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-630x-8000-000x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0752-8303-8000-0002","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-340x","version":"affected 1.0.0 4.8.9 semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0751-9x01","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0750-811x-xxxx-xxxx","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0750-821x-xxx-xxx","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-420x-8000-000x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-430x-8000-000x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-520x-8000-000x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-530x-8000-000x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-620x-8000-000x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-630x-8000-000x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0752-8303-8000-0002","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]},{"source":"CNA","vendor":"WAGO","product":"0762-340x","version":"affected 1.0.0 4.8.9 (70) semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-41753","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-10-01T19:11:00.419667Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T19:11:15.337Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"0751-9x01","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0750-811x-xxxx-xxxx","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0750-821x-xxx-xxx","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-420x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-430x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-520x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-530x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-620x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-630x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0752-8303-8000-0002","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-340x","vendor":"WAGO","versions":[{"lessThan":"4.8.9","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0751-9x01","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0750-811x-xxxx-xxxx","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0750-821x-xxx-xxx","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-420x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-430x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-520x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-530x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-620x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-630x-8000-000x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0752-8303-8000-0002","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"0762-340x","vendor":"WAGO","versions":[{"lessThan":"4.8.9 (70)","status":"affected","version":"1.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.</p>"}],"value":"The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T06:42:00.734Z","orgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","shortName":"CERTVDE"},"references":[{"url":"https://www.certvde.com/en/advisories/VDE-2025-102/"}],"source":{"advisory":"VDE-2025-102","defect":["CERT@VDE#641894"],"discovery":"UNKNOWN"},"title":"Path traversal in dynamically created BACnet File Objects","x_generator":{"engine":"Vulnogram 0.4.0"}}},"cveMetadata":{"assignerOrgId":"270ccfa6-a436-4e77-922e-914ec3a9685c","assignerShortName":"CERTVDE","cveId":"CVE-2025-41753","datePublished":"2026-10-01T06:42:00.734Z","dateReserved":"2025-04-16T11:18:45.759Z","dateUpdated":"2026-10-01T19:11:15.337Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 07:16:32","lastModifiedDate":"2026-10-01 20:17:20","problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":{"cvssMetricV40":[{"source":"info@cert.vde.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"info@cert.vde.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T19:11:00.419667Z","id":"CVE-2025-41753","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"41753","Ordinal":"1","Title":"Path traversal in dynamically created BACnet File Objects","CVE":"CVE-2025-41753","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"41753","Ordinal":"1","NoteData":"The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.","Type":"Description","Title":"Path traversal in dynamically created BACnet File Objects"}]}}}