Weidmueller Weidmueller

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Weidmueller product.

RSS Feeds for Weidmueller security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Weidmueller products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Weidmueller Sorted by Most Security Vulnerabilities since 2018

Weidmueller Wi Manager1 vulnerability

By the Year

In 2026 there have been 3 vulnerabilities in Weidmueller with an average score of 9.3 out of ten. Weidmueller did not have any published security vulnerabilities last year. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 3 9.30
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 7.30

It may take a day or so for new Weidmueller vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Weidmueller Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-63587 Aug 25, 2026
IE-SR-2TX-WL-4G SMS Auth Bypass via Failed Password Counter Reset The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
Fwr Ie Sr 2tx Wl 4g Eu Us
CVE-2026-63586 Aug 25, 2026
uhttpd CGI Shell Escalation via Unsanitized HTTP Auth Username The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.
Fwr Ie Sr 2tx Wl
Fwr Ie Sr 2tx Wl 4g Eu Us
CVE-2026-16462 Jul 28, 2026
SQLi via unsanitized GetGridData in PROCON-WEB SCADA In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
Procon Web Scada
CVE-2020-12525 Jan 22, 2021
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Wi Manager
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.