{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/ads-tec-industrial-it/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-14169"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DVG-IRF1401","DVG-IRF1421","DVG-IRF3401","DVG-IRF3421","DVG-IRF3801","DVG-IRF3821"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","denial-of-service","industrial-control-systems","network-device"],"_cs_type":"advisory","_cs_vendors":["ads-tec Industrial IT"],"content_html":"\u003cp\u003eCVE-2026-14169 details a high-severity vulnerability affecting ads-tec Industrial IT DVG-IRF series devices, including models DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, and DVG-IRF3821, specifically versions prior to 2.3.0. A low-privileged remote attacker can exploit an \u0026quot;Incorrect Behavior Order\u0026quot; (CWE-696) flaw by sending specially crafted input. This manipulation allows the attacker to trigger an inconsistent account state, leading to the overwriting of existing user passwords. The vulnerability's exploitation results in complete administrative unavailability of the affected device, posing a significant operational risk for organizations utilizing these industrial IT products due to the loss of control and potential for disruption.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA low-privileged remote attacker identifies an exposed ads-tec Industrial IT DVG-IRF series device.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts specific input designed to exploit the \u0026quot;Incorrect Behavior Order\u0026quot; (CWE-696) vulnerability (CVE-2026-14169).\u003c/li\u003e\n\u003cli\u003eThis crafted input is sent to the vulnerable device over the network.\u003c/li\u003e\n\u003cli\u003eDue to the improper sequencing of internal operations within the device, it enters an inconsistent account state.\u003c/li\u003e\n\u003cli\u003eThe inconsistent state allows the attacker's crafted input to successfully overwrite existing administrative user passwords.\u003c/li\u003e\n\u003cli\u003eLegitimate administrators are locked out of the device, rendering it administratively unavailable.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves their objective of causing denial of administrative access to the device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-14169 results in complete administrative unavailability of the affected ads-tec Industrial IT DVG-IRF series devices (models DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821, all versions prior to 2.3.0). Attackers can overwrite existing user passwords, effectively locking out legitimate administrators from managing the device. This could lead to severe operational disruptions, as critical industrial control or network infrastructure managed by these devices becomes unmanageable, potentially requiring physical access or device reset for recovery. The loss of administrative control could enable further compromise or disruption depending on the device's specific function in the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-14169 on all affected ads-tec Industrial IT DVG-IRF series devices by upgrading to version 2.3.0 or later.\u003c/li\u003e\n\u003cli\u003eConsult the CERT VDE advisory at \u003ca href=\"https://www.certvde.com/en/advisories/VDE-2026-076/\"\u003ehttps://www.certvde.com/en/advisories/VDE-2026-076/\u003c/a\u003e for vendor-specific patch availability and deployment instructions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T09:22:56Z","date_published":"2026-07-28T09:22:56Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14169-ads-tec-dvg-irf-vulnerability/","summary":"A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.","title":"CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14169-ads-tec-dvg-irf-vulnerability/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14168"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DVG-IRF1401 (\u003c 2.3.0)","DVG-IRF1421 (\u003c 2.3.0)","DVG-IRF3401 (\u003c 2.3.0)","DVG-IRF3421 (\u003c 2.3.0)","DVG-IRF3801 (\u003c 2.3.0)","DVG-IRF3821 (\u003c 2.3.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","missing-authorization","industrial-control-system","embedded-device"],"_cs_type":"advisory","_cs_vendors":["ads-tec Industrial IT"],"content_html":"\u003cp\u003eCVE-2026-14168 is a high-severity privilege escalation vulnerability affecting multiple ads-tec Industrial IT DVG-IRF series products, specifically versions prior to 2.3.0. The vulnerability stems from a critical missing authorization check (CWE-862) at the \u0026quot;insert path of the configuration table.\u0026quot; This flaw enables a remote attacker with low-level privileges to bypass security controls and arbitrarily modify the device's configuration. By exploiting this, an attacker can create new administrative accounts or elevate the privileges of an existing low-privileged account, leading to full compromise of the system. The vulnerability has a CVSS v3.1 base score of 8.8 (High). This vulnerability poses a significant risk to the integrity and confidentiality of industrial control systems using these devices, as it allows unauthorized control and potential disruption of critical operations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA remote attacker with existing low-privileged credentials gains network access to a vulnerable ads-tec Industrial IT DVG-IRF series device (version \u0026lt; 2.3.0).\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the specific \u0026quot;insert path of the configuration table\u0026quot; endpoint or mechanism within the device's management interface.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious request targeting this identified configuration endpoint, designed to either modify an existing user's privileges or create a new user with administrative rights.\u003c/li\u003e\n\u003cli\u003eDue to the critical missing authorization check (CWE-862) associated with the configuration table's insert path, the device fails to properly validate the attacker's insufficient permissions for the proposed administrative change.\u003c/li\u003e\n\u003cli\u003eThe device processes the unauthorized configuration modification request, successfully updating the internal configuration table to grant administrative privileges to the attacker-controlled account.\u003c/li\u003e\n\u003cli\u003eThe attacker then authenticates to the DVG-IRF device using the newly acquired administrator credentials.\u003c/li\u003e\n\u003cli\u003eUpon successful authentication, the attacker gains full system access and control over the vulnerable industrial device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14168 allows a low-privileged attacker to escalate to full administrator privileges on the affected ads-tec Industrial IT DVG-IRF series products. This complete system access means the attacker can manipulate, disrupt, or completely shut down the affected device. In industrial environments, this could lead to operational downtime, compromise sensitive data, or allow for further lateral movement into critical infrastructure. Given that these devices are often used in sensitive industrial IT contexts, the direct impact on system integrity and availability could be severe, potentially affecting production lines, safety systems, or data integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-14168 immediately by upgrading ads-tec Industrial IT DVG-IRF series products to version 2.3.0 or later as recommended by CERT VDE and ads-tec Industrial IT.\u003c/li\u003e\n\u003cli\u003eReview network segmentation to limit direct remote access to affected ads-tec Industrial IT DVG-IRF devices to only necessary management networks.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual configuration changes or attempts to modify user privileges, particularly related to the \u0026quot;insert path of the configuration table\u0026quot; which is referenced in CVE-2026-14168.\u003c/li\u003e\n\u003cli\u003eImplement strong authentication mechanisms and enforce the principle of least privilege for all users accessing ads-tec Industrial IT DVG-IRF devices.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T09:21:55Z","date_published":"2026-07-28T09:21:55Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14168-ads-tec-privesc/","summary":"A high-severity missing authorization vulnerability, CVE-2026-14168, allows a low-privileged remote attacker to escalate privileges to administrator level by exploiting the insert path of the configuration table in ads-tec Industrial IT DVG-IRF series products, ultimately granting full system access.","title":"CVE-2026-14168: ads-tec Industrial IT DVG-IRF Privilege Escalation","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14168-ads-tec-privesc/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14167"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DVG-IRF1401 (versions \u003c 2.3.0)","DVG-IRF1421 (versions \u003c 2.3.0)","DVG-IRF3401 (versions \u003c 2.3.0)","DVG-IRF3421 (versions \u003c 2.3.0)","DVG-IRF3801 (versions \u003c 2.3.0)","DVG-IRF3821 (versions \u003c 2.3.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","authorization-bypass","ICS","OT"],"_cs_type":"advisory","_cs_vendors":["ads-tec Industrial IT"],"content_html":"\u003cp\u003eCVE-2026-14167 describes a critical authorization bypass vulnerability affecting several ads-tec Industrial IT DVG-IRF series products, including DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, and DVG-IRF3821 with versions prior to 2.3.0. This flaw allows a low-privileged remote attacker to circumvent authorization checks and execute configuration changes that are typically restricted to administrator-level users. This includes sensitive actions such as managing system permissions, potentially leading to complete compromise of the affected devices. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), highlighting its severe impact on confidentiality, integrity, and availability. Organizations using these industrial IT devices are strongly advised to review their deployed versions and apply updates to prevent unauthorized access and control.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access\u003c/strong\u003e: A remote attacker gains low-privileged access to an affected ads-tec Industrial IT DVG-IRF series device. The method for initial low-privileged access is not detailed but typically involves legitimate credentials or another, less severe vulnerability.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAuthorization Bypass\u003c/strong\u003e: The attacker identifies and exploits the incorrect authorization vulnerability (CWE-863) within the device's management interface or API.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivileged Configuration Change Request\u003c/strong\u003e: The attacker crafts and sends requests to the device's management interface or API, attempting to modify configuration settings that usually require administrator privileges.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSystem Accepts Unauthorized Change\u003c/strong\u003e: Due to the authorization bypass, the device incorrectly validates the attacker's low-privileged session as having sufficient permissions.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePermission Management\u003c/strong\u003e: The attacker successfully executes privileged actions, such as modifying user permissions, creating new administrative accounts, or altering critical system settings.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivilege Escalation\u003c/strong\u003e: The attacker elevates their privileges on the device, gaining full administrative control over the affected industrial IT product.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSystem Compromise\u003c/strong\u003e: With administrative control, the attacker can manipulate device functions, inject malicious configurations, access sensitive data, or disrupt operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14167 grants a low-privileged remote attacker the ability to perform administrative actions, leading to a complete compromise of the affected ads-tec Industrial IT DVG-IRF series devices. This can result in unauthorized access to sensitive operational technology (OT) or industrial control system (ICS) configurations, disruption of critical infrastructure processes, or data manipulation. Given these are industrial IT products, the impact could extend to significant operational downtime, safety hazards, environmental damage, or severe financial losses. The specific number of affected organizations or observed exploitation is not detailed, but the high CVSS score indicates a substantial risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch all affected ads-tec Industrial IT DVG-IRF series products (DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821) to version 2.3.0 or later as advised in the CERT VDE advisory for CVE-2026-14167.\u003c/li\u003e\n\u003cli\u003eReview network segmentation and access control policies for devices listed in the affected_products section to minimize exposure to unauthorized remote access.\u003c/li\u003e\n\u003cli\u003eMonitor authentication and authorization logs for unusual configuration changes or login attempts on ads-tec Industrial IT devices.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T09:21:02Z","date_published":"2026-07-28T09:21:02Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14167/","summary":"A low-privileged remote attacker can exploit CVE-2026-14167, an incorrect authorization vulnerability in multiple ads-tec Industrial IT DVG-IRF series products, to perform privileged configuration changes, including permission management, leading to privilege escalation.","title":"CVE-2026-14167: ads-tec Industrial IT DVG-IRF Series Privilege Escalation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14167/"}],"language":"en","title":"CraftedSignal Threat Feed - Ads-Tec Industrial IT","version":"https://jsonfeed.org/version/1.1"}