Executive brief
ADS-TEC Industrial IT IRF series routers are affected by a security flaw in their web management interface. An attacker can create a specially crafted link that, after a user logs in, automatically redirects them to a malicious external website. This can be used in phishing campaigns to steal user credentials or deliver malware by making the malicious site appear to be a legitimate part of the device's configuration process.
Technical details
The vulnerability is an Open Redirect (CWE-601) located in the web-based user interface of ADS-TEC IRF1000 and IRF3000 industrial routers. The application fails to properly validate the destination URL in the post-login redirect parameter. An unauthenticated remote attacker can craft a URL that points to the legitimate login page but includes a malicious external site in the redirect parameter. If a user follows this link and successfully authenticates, the browser will automatically navigate to the untrusted site. This flaw is fixed in firmware version 2.3.0.
Affected products
- ads-tec Industrial IT DVG-IRF1401 (IRF1000) 2.2.5 to < 2.3.0
- ads-tec Industrial IT DVG-IRF1421 (IRF1000) 2.2.5 to < 2.3.0
- ads-tec Industrial IT DVG-IRF3401 (IRF3000) 2.2.5 to < 2.3.0
- ads-tec Industrial IT DVG-IRF3421 (IRF3000) 2.2.5 to < 2.3.0
- ads-tec Industrial IT DVG-IRF3801 (IRF3000) 2.2.5 to < 2.3.0
- ads-tec Industrial IT DVG-IRF3821 (IRF3000) 2.2.5 to < 2.3.0
Timeline
- 2026-07-28: advisory
- 2026-07-28: patched