Junglewise Threat Intelligence

CVE-2026-14168: ads-tec Industrial IT IRF Products missing authorization in configuration table

CVE-2026-14168 · Severity: high · CVSS 8.8 · Published 2026-07-28

Technologies: ads-tec Industrial IT DVG-IRF3821, ads-tec Industrial IT DVG-IRF1401, ads-tec Industrial IT DVG-IRF3801, ads-tec Industrial IT DVG-IRF3421, ads-tec Industrial IT DVG-IRF3401, ads-tec Industrial IT DVG-IRF1421. Vendors: ads-tec Industrial IT.

Executive brief

ADS-TEC Industrial IT IRF1000 and IRF3000 series industrial firewalls and routers are affected by a security flaw that allows a user with low-level access to gain full administrator control. By exploiting a missing security check in the device's configuration interface, an attacker can take over the system, potentially leading to unauthorized network changes or data exposure. This could compromise the security of the industrial environment the device is intended to protect.

Technical details

A missing authorization vulnerability (CWE-862) exists in the proprietary configuration interface of ADS-TEC IRF1000 and IRF3000 series products. The flaw is located in the 'insert path' of the configuration table, where the system fails to verify if the requesting user has the appropriate permissions to perform administrative actions. A remote attacker with low-privileged credentials can exploit this over the network to escalate their privileges to administrator level. This grant of full system access allows for complete control over the device configuration. The issue is resolved in firmware version 2.3.0.

Affected products

  • ads-tec Industrial IT DVG-IRF1401 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF1421 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3401 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3421 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3801 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3821 1.0.0 to <2.3.0

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: patched: Fixed in firmware version 2.3.0

References

Related threats