Executive brief
A vulnerability exists in TURCK Managed Ethernet Switches, which are used to connect and manage industrial network devices. An attacker with low-level access to the device can take complete control of the switch by injecting malicious commands through a specific naming parameter. This could lead to a total loss of network availability, unauthorized access to industrial data, or a foothold for further attacks on the corporate or production network.
Technical details
A command injection vulnerability (CWE-78) exists in the firmware of TURCK TBEN-Lx-SE-M2 Managed Ethernet Switches. The flaw is rooted in the improper neutralization of special elements within a 'name' parameter, allowing an attacker to execute arbitrary OS commands. Exploitation requires network reachability and low-privileged authentication. Successful exploitation results in full system compromise, impacting confidentiality, integrity, and availability. The vulnerability is addressed in firmware version 2.1.2.0.
Affected products
- TURCK TBEN-L4-SE-M2 Firmware < 2.1.2.0
- TURCK TBEN-L5-SE-M2 Firmware < 2.1.2.0
- TURCK TBEN-LL-SE-M2 Firmware < 2.1.2.0
Timeline
- 2026-05-19: advisory: Initial advisory released by CERT@VDE and TURCK
- 2026-06-16: disclosed: CVE published to NVD dataset