{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/dvg-irf1401/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-14169"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DVG-IRF1401","DVG-IRF1421","DVG-IRF3401","DVG-IRF3421","DVG-IRF3801","DVG-IRF3821"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","denial-of-service","industrial-control-systems","network-device"],"_cs_type":"advisory","_cs_vendors":["ads-tec Industrial IT"],"content_html":"\u003cp\u003eCVE-2026-14169 details a high-severity vulnerability affecting ads-tec Industrial IT DVG-IRF series devices, including models DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, and DVG-IRF3821, specifically versions prior to 2.3.0. A low-privileged remote attacker can exploit an \u0026quot;Incorrect Behavior Order\u0026quot; (CWE-696) flaw by sending specially crafted input. This manipulation allows the attacker to trigger an inconsistent account state, leading to the overwriting of existing user passwords. The vulnerability's exploitation results in complete administrative unavailability of the affected device, posing a significant operational risk for organizations utilizing these industrial IT products due to the loss of control and potential for disruption.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA low-privileged remote attacker identifies an exposed ads-tec Industrial IT DVG-IRF series device.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts specific input designed to exploit the \u0026quot;Incorrect Behavior Order\u0026quot; (CWE-696) vulnerability (CVE-2026-14169).\u003c/li\u003e\n\u003cli\u003eThis crafted input is sent to the vulnerable device over the network.\u003c/li\u003e\n\u003cli\u003eDue to the improper sequencing of internal operations within the device, it enters an inconsistent account state.\u003c/li\u003e\n\u003cli\u003eThe inconsistent state allows the attacker's crafted input to successfully overwrite existing administrative user passwords.\u003c/li\u003e\n\u003cli\u003eLegitimate administrators are locked out of the device, rendering it administratively unavailable.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves their objective of causing denial of administrative access to the device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-14169 results in complete administrative unavailability of the affected ads-tec Industrial IT DVG-IRF series devices (models DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821, all versions prior to 2.3.0). Attackers can overwrite existing user passwords, effectively locking out legitimate administrators from managing the device. This could lead to severe operational disruptions, as critical industrial control or network infrastructure managed by these devices becomes unmanageable, potentially requiring physical access or device reset for recovery. The loss of administrative control could enable further compromise or disruption depending on the device's specific function in the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-14169 on all affected ads-tec Industrial IT DVG-IRF series devices by upgrading to version 2.3.0 or later.\u003c/li\u003e\n\u003cli\u003eConsult the CERT VDE advisory at \u003ca href=\"https://www.certvde.com/en/advisories/VDE-2026-076/\"\u003ehttps://www.certvde.com/en/advisories/VDE-2026-076/\u003c/a\u003e for vendor-specific patch availability and deployment instructions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T09:22:56Z","date_published":"2026-07-28T09:22:56Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14169-ads-tec-dvg-irf-vulnerability/","summary":"A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.","title":"CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14169-ads-tec-dvg-irf-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - DVG-IRF1401","version":"https://jsonfeed.org/version/1.1"}