Junglewise Threat Intelligence

CVE-2026-14171: ads-tec Industrial IT IRF Products open redirect in web-UI

CVE-2026-14171 · Severity: medium · CVSS 6.1 · Published 2026-07-28

Technologies: ads-tec Industrial IT DVG-IRF3821, ads-tec Industrial IT DVG-IRF1401, ads-tec Industrial IT DVG-IRF3801, ads-tec Industrial IT DVG-IRF3421, ads-tec Industrial IT DVG-IRF3401, ads-tec Industrial IT DVG-IRF1421. Vendors: ads-tec Industrial IT.

Executive brief

ADS-TEC Industrial IT IRF series routers are affected by a security flaw in their web management interface. An attacker can create a specially crafted link that, after a user logs in, automatically redirects them to a malicious external website. This can be used in phishing campaigns to steal user credentials or deliver malware by making the malicious site appear to be a legitimate part of the device's configuration process.

Technical details

The vulnerability is an Open Redirect (CWE-601) located in the web-based user interface of ADS-TEC IRF1000 and IRF3000 industrial routers. The application fails to properly validate the destination URL in the post-login redirect parameter. An unauthenticated remote attacker can craft a URL that points to the legitimate login page but includes a malicious external site in the redirect parameter. If a user follows this link and successfully authenticates, the browser will automatically navigate to the untrusted site. This flaw is fixed in firmware version 2.3.0.

Affected products

  • ads-tec Industrial IT DVG-IRF1401 (IRF1000) 2.2.5 to < 2.3.0
  • ads-tec Industrial IT DVG-IRF1421 (IRF1000) 2.2.5 to < 2.3.0
  • ads-tec Industrial IT DVG-IRF3401 (IRF3000) 2.2.5 to < 2.3.0
  • ads-tec Industrial IT DVG-IRF3421 (IRF3000) 2.2.5 to < 2.3.0
  • ads-tec Industrial IT DVG-IRF3801 (IRF3000) 2.2.5 to < 2.3.0
  • ads-tec Industrial IT DVG-IRF3821 (IRF3000) 2.2.5 to < 2.3.0

Timeline

  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats