Executive brief
ADS-TEC Industrial IT IRF1000 and IRF3000 series industrial firewalls and routers are affected by a security flaw that allows a user with low-level access to gain full administrator control. By exploiting a missing security check in the device's configuration interface, an attacker can take over the system, potentially leading to unauthorized network changes or data exposure. This could compromise the security of the industrial environment the device is intended to protect.
Technical details
A missing authorization vulnerability (CWE-862) exists in the proprietary configuration interface of ADS-TEC IRF1000 and IRF3000 series products. The flaw is located in the 'insert path' of the configuration table, where the system fails to verify if the requesting user has the appropriate permissions to perform administrative actions. A remote attacker with low-privileged credentials can exploit this over the network to escalate their privileges to administrator level. This grant of full system access allows for complete control over the device configuration. The issue is resolved in firmware version 2.3.0.
Affected products
- ads-tec Industrial IT DVG-IRF1401 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF1421 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3401 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3421 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3801 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3821 1.0.0 to <2.3.0
Timeline
- 2026-07-28: disclosed
- 2026-07-28: patched: Fixed in firmware version 2.3.0