Executive brief
A vulnerability exists in the web management interface of Nordex N149 wind turbines, which are used for large-scale renewable energy generation. An unauthorized attacker can exploit this flaw to bypass security logins and access the internal database. This could lead to the theft of sensitive operational data or unauthorized access to the turbine's management system.
Technical details
An unauthenticated SQL injection vulnerability exists in the login.php component of the Nordex N149/4.0-4.5 Wind Turbine Web Server. The root cause is improper neutralization of special elements in the 'login' POST parameter. A remote attacker can send crafted HTTP POST requests containing SQL payloads to the vulnerable endpoint. Successful exploitation allows the attacker to execute arbitrary SQL commands, which can be used to extract sensitive information from the database or bypass authentication mechanisms to gain administrative access to the web interface. Proof-of-concept exploits have been publicly disclosed.
Affected products
- Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 - 4.5
Timeline
- 2018-05-21: disclosed: Initial discovery and exploit publication by t4rkd3vilz
- 2026-05-17: advisory: CVE record published and enriched by VulnCheck/NVD