Executive brief
ADS-TEC Industrial IT firewalls and routers are affected by a security flaw that allows a user with low-level access to perform administrative tasks. An attacker could change critical device settings or modify user permissions, potentially leading to a full takeover of the network hardware. This could result in unauthorized network access, data interception, or service disruptions.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the proprietary configuration interface and web UI of ADS-TEC IRF1000 and IRF3000 series products. A remote attacker with low-privileged credentials can bypass intended access controls to perform administrative configuration changes, including the management of user permissions. This flaw allows for vertical privilege escalation from a standard user to an administrator. The vulnerability is addressed in firmware version 2.3.0.
Affected products
- ads-tec Industrial IT DVG-IRF1401 (IRF1000) 1.0.0 to 2.2.9
- ads-tec Industrial IT DVG-IRF1421 (IRF1000) 1.0.0 to 2.2.9
- ads-tec Industrial IT DVG-IRF3401 (IRF3000) 1.0.0 to 2.2.9
- ads-tec Industrial IT DVG-IRF3421 (IRF3000) 1.0.0 to 2.2.9
- ads-tec Industrial IT DVG-IRF3801 (IRF3000) 1.0.0 to 2.2.9
- ads-tec Industrial IT DVG-IRF3821 (IRF3000) 1.0.0 to 2.2.9
Timeline
- 2026-07-28: advisory
- 2026-07-28: patched: Fixed in firmware version 2.3.0