Junglewise Threat Intelligence

CVE-2026-14169: ads-tec Industrial IT IRF series password overwrite via incorrect behavior order

CVE-2026-14169 · Severity: high · CVSS 8.1 · Published 2026-07-28

Technologies: ads-tec Industrial IT DVG-IRF3821, ads-tec Industrial IT DVG-IRF1401, ads-tec Industrial IT DVG-IRF3801, ads-tec Industrial IT DVG-IRF3421, ads-tec Industrial IT DVG-IRF3401, ads-tec Industrial IT DVG-IRF1421. Vendors: ads-tec Industrial IT.

Executive brief

ADS-TEC Industrial IT IRF series firewalls and routers are affected by a security flaw that allows a user with low-level access to lock others out of the system. By sending specifically crafted input, an attacker can overwrite existing user passwords and put the device into an inconsistent state. This can result in a total loss of administrative access, preventing legitimate managers from configuring or maintaining the network equipment.

Technical details

A vulnerability classified as Incorrect Behavior Order (CWE-696) exists in the configuration interface of ADS-TEC IRF1000 and IRF3000 series devices. A remote attacker with low-privileged credentials can provide crafted input that exploits the sequence of operations within the account management logic. This allows the attacker to overwrite the passwords of other existing users, including administrators. Successful exploitation results in a denial-of-service condition regarding device management (administrative unavailability). The issue is resolved in firmware version 2.3.0.

Affected products

  • ads-tec Industrial IT DVG-IRF1401 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF1421 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3401 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3421 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3801 1.0.0 to <2.3.0
  • ads-tec Industrial IT DVG-IRF3821 1.0.0 to <2.3.0

Timeline

  • 2026-07-28: advisory: Advisory VDE-2026-076 published by CERT@VDE
  • 2026-07-28: disclosed: CVE-2026-14169 published to NVD

References

Related threats