Executive brief
ADS-TEC Industrial IT IRF series firewalls and routers are affected by a security flaw that allows a user with low-level access to lock others out of the system. By sending specifically crafted input, an attacker can overwrite existing user passwords and put the device into an inconsistent state. This can result in a total loss of administrative access, preventing legitimate managers from configuring or maintaining the network equipment.
Technical details
A vulnerability classified as Incorrect Behavior Order (CWE-696) exists in the configuration interface of ADS-TEC IRF1000 and IRF3000 series devices. A remote attacker with low-privileged credentials can provide crafted input that exploits the sequence of operations within the account management logic. This allows the attacker to overwrite the passwords of other existing users, including administrators. Successful exploitation results in a denial-of-service condition regarding device management (administrative unavailability). The issue is resolved in firmware version 2.3.0.
Affected products
- ads-tec Industrial IT DVG-IRF1401 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF1421 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3401 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3421 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3801 1.0.0 to <2.3.0
- ads-tec Industrial IT DVG-IRF3821 1.0.0 to <2.3.0
Timeline
- 2026-07-28: advisory: Advisory VDE-2026-076 published by CERT@VDE
- 2026-07-28: disclosed: CVE-2026-14169 published to NVD