2026-07-28 9:7CVE-2026-14168CERTVDE
PUBLISHED5.2CWE-862

ads-tec Industrial IT: Vertical privilege escalation via configuration table write

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

Problem type

Affected products

ads-tec Industrial IT

DVG-IRF1401

< 2.3.0 - AFFECTED

DVG-IRF1421

< 2.3.0 - AFFECTED

DVG-IRF3401

< 2.3.0 - AFFECTED

DVG-IRF3421

< 2.3.0 - AFFECTED

DVG-IRF3801

< 2.3.0 - AFFECTED

DVG-IRF3821

< 2.3.0 - AFFECTED

References

GitHub Security Advisories

GHSA-h5wj-mjq4-7p64

A low privileged remote attacker can gain administrator privileges due to missing authorization...

https://github.com/advisories/GHSA-h5wj-mjq4-7p64

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-14168
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-14168",
    "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
    "assignerShortName": "CERTVDE",
    "dateUpdated": "2026-07-28T12:46:30.943Z",
    "dateReserved": "2026-06-30T06:39:05.718Z",
    "datePublished": "2026-07-28T09:07:26.723Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "shortName": "CERTVDE",
        "dateUpdated": "2026-07-28T09:07:26.723Z"
      },
      "title": "ads-tec Industrial IT: Vertical privilege escalation via configuration table write",
      "descriptions": [
        {
          "lang": "en",
          "value": "A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "ads-tec Industrial IT",
          "product": "DVG-IRF1401",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.3.0"
            }
          ]
        },
        {
          "vendor": "ads-tec Industrial IT",
          "product": "DVG-IRF1421",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.3.0"
            }
          ]
        },
        {
          "vendor": "ads-tec Industrial IT",
          "product": "DVG-IRF3401",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.3.0"
            }
          ]
        },
        {
          "vendor": "ads-tec Industrial IT",
          "product": "DVG-IRF3421",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.3.0"
            }
          ]
        },
        {
          "vendor": "ads-tec Industrial IT",
          "product": "DVG-IRF3801",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.3.0"
            }
          ]
        },
        {
          "vendor": "ads-tec Industrial IT",
          "product": "DVG-IRF3821",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.3.0"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-862 Missing Authorization",
              "cweId": "CWE-862",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-076/"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH"
          }
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-07-28T12:46:30.943Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}