Skip to content
Threat Feed
medium advisory

CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout

A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.

CVE-2026-14169 details a high-severity vulnerability affecting ads-tec Industrial IT DVG-IRF series devices, including models DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, and DVG-IRF3821, specifically versions prior to 2.3.0. A low-privileged remote attacker can exploit an "Incorrect Behavior Order" (CWE-696) flaw by sending specially crafted input. This manipulation allows the attacker to trigger an inconsistent account state, leading to the overwriting of existing user passwords. The vulnerability's exploitation results in complete administrative unavailability of the affected device, posing a significant operational risk for organizations utilizing these industrial IT products due to the loss of control and potential for disruption.

Attack Chain

  1. A low-privileged remote attacker identifies an exposed ads-tec Industrial IT DVG-IRF series device.
  2. The attacker crafts specific input designed to exploit the "Incorrect Behavior Order" (CWE-696) vulnerability (CVE-2026-14169).
  3. This crafted input is sent to the vulnerable device over the network.
  4. Due to the improper sequencing of internal operations within the device, it enters an inconsistent account state.
  5. The inconsistent state allows the attacker's crafted input to successfully overwrite existing administrative user passwords.
  6. Legitimate administrators are locked out of the device, rendering it administratively unavailable.
  7. The attacker achieves their objective of causing denial of administrative access to the device.

Impact

The successful exploitation of CVE-2026-14169 results in complete administrative unavailability of the affected ads-tec Industrial IT DVG-IRF series devices (models DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821, all versions prior to 2.3.0). Attackers can overwrite existing user passwords, effectively locking out legitimate administrators from managing the device. This could lead to severe operational disruptions, as critical industrial control or network infrastructure managed by these devices becomes unmanageable, potentially requiring physical access or device reset for recovery. The loss of administrative control could enable further compromise or disruption depending on the device's specific function in the environment.

Recommendation

  • Patch CVE-2026-14169 on all affected ads-tec Industrial IT DVG-IRF series devices by upgrading to version 2.3.0 or later.
  • Consult the CERT VDE advisory at https://www.certvde.com/en/advisories/VDE-2026-076/ for vendor-specific patch availability and deployment instructions.