Junglewise Threat Intelligence

CVE-2026-14167: ads-tec Industrial IT IRF Products incorrect authorization in Web UI

CVE-2026-14167 · Severity: high · CVSS 8.8 · Published 2026-07-28

Technologies: ads-tec Industrial IT DVG-IRF3821, ads-tec Industrial IT DVG-IRF1401, ads-tec Industrial IT DVG-IRF3801, ads-tec Industrial IT DVG-IRF3421, ads-tec Industrial IT DVG-IRF3401, ads-tec Industrial IT DVG-IRF1421. Vendors: ads-tec Industrial IT.

Executive brief

ADS-TEC Industrial IT firewalls and routers are affected by a security flaw that allows a user with low-level access to perform administrative tasks. An attacker could change critical device settings or modify user permissions, potentially leading to a full takeover of the network hardware. This could result in unauthorized network access, data interception, or service disruptions.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the proprietary configuration interface and web UI of ADS-TEC IRF1000 and IRF3000 series products. A remote attacker with low-privileged credentials can bypass intended access controls to perform administrative configuration changes, including the management of user permissions. This flaw allows for vertical privilege escalation from a standard user to an administrator. The vulnerability is addressed in firmware version 2.3.0.

Affected products

  • ads-tec Industrial IT DVG-IRF1401 (IRF1000) 1.0.0 to 2.2.9
  • ads-tec Industrial IT DVG-IRF1421 (IRF1000) 1.0.0 to 2.2.9
  • ads-tec Industrial IT DVG-IRF3401 (IRF3000) 1.0.0 to 2.2.9
  • ads-tec Industrial IT DVG-IRF3421 (IRF3000) 1.0.0 to 2.2.9
  • ads-tec Industrial IT DVG-IRF3801 (IRF3000) 1.0.0 to 2.2.9
  • ads-tec Industrial IT DVG-IRF3821 (IRF3000) 1.0.0 to 2.2.9

Timeline

  • 2026-07-28: advisory
  • 2026-07-28: patched: Fixed in firmware version 2.3.0

References

Related threats