Sceawere

Vulnerability Detail

CVE-2025-41753UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BACnet File Object Path Traversal

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
WAGO
Product
0751-9x01
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-01T07:16:32.473Z",
  "pubdate": "2026-10-01T07:16:32.473Z",
  "executiveSummary": "The vulnerability is a path traversal flaw residing within the handling of dynamically created BACnet File Objects. It allows unauthenticated remote attackers to bypass directory restrictions by supplying malicious file names during object creation or access requests.\nBy manipulating the object name, an attacker can traverse the file system hierarchy outside the designated storage directory. This grants the capability to read sensitive configuration or system files, as well as overwrite critical system components.\nThe impact is severe, potentially leading to full system compromise, loss of confidentiality, integrity, and availability. The vulnerability is exploitable over the network without requiring prior authentication, significantly increasing the risk surface for affected industrial control devices.\nSuccessful exploitation requires the attacker to have network reachability to the BACnet-enabled device. Once access is established, the attacker can leverage standard BACnet services to perform unauthorized file operations, effectively bypassing access control mechanisms implemented by the device firmware.",
  "technicalDetails": "The root cause of this vulnerability is the improper neutralization of input used in file path construction. The BACnet implementation fails to sanitize the 'object name' field of dynamically created BACnet File Objects, treating the provided string as a literal file path rather than a constrained identifier within an isolated sandbox.\nWhen a remote actor initiates a write or read request using a crafted BACnet object name, the underlying system processes the request using relative path nomenclature. Because the application logic does not perform canonicalization or validate that the resulting path resolves to an authorized directory, an attacker can utilize sequences like '../' to escape the intended scope.\nThe attack flow begins when an attacker identifies the relevant BACnet instance. Using standard BACnet protocols, the attacker issues a request to manipulate a File Object. By injecting path traversal sequences into the object name parameter, the attacker forces the system's file I/O operations to point to arbitrary locations on the device filesystem.\nIn a read-oriented attack, the attacker triggers an object read request where the path points to sensitive files such as /etc/passwd or application configuration files containing authentication tokens or network keys. The system, failing to verify the boundary of the request, returns the contents of the targeted file back to the attacker.\nIn a write-oriented attack, the attacker creates or modifies a File Object directed at sensitive system binaries or startup scripts. By overwriting these files, the attacker can achieve remote code execution, persisting their access across device reboots.\nThis vulnerability is particularly dangerous because it bypasses typical authentication mechanisms, as BACnet services are often exposed without rigorous perimeter defenses in industrial networks. The lack of input validation at the application layer means the file system is exposed as long as the service is active and reachable via the BACnet protocol stack.\nThe exposure extends to any file the user process running the BACnet stack has permission to access. In many embedded environments, these services run with elevated or root privileges, meaning the path traversal vulnerability effectively grants the attacker the same level of access as the service itself."
}
CVE-2025-41753: BACnet File Object Path Traversal (CRITICAL Severity, CVSS: 9.8) | Sceawere