CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “weidmueller”

20 vulnerabilities found for “weidmueller”

CVE-2022-3073
MEDIUM6.1

Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.

weidmueller / 19_iot_md01_lan_h4_s0011_firmware+8
Network
Published Dec 14, 2022
CVE-2021-33537
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33534
HIGH7.2

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33528
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33533
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33539
HIGH7.2

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33538
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33531
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. An attacker can send diagnostic scripts while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33530
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33536
HIGH7.5

In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in ServiceAgent functionality. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33535
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33532
HIGH8.8

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-33529
HIGH7.5

In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.

weidmueller / ie-wl-bl-ap-cl-eu_firmware+15
Network
Published Jun 25, 2021
CVE-2021-20999
CRITICAL9.4

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

weidmueller / uc20-wl2000-ac_firmware+15
Network
Published May 13, 2021
CVE-2020-12525
HIGH7.3

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

emerson / rosemount_transmitter_interface_software+10
Local
Published Jan 22, 2021
CVE-2019-16671
MEDIUM6.5

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special packet because of Uncontrolled Resource Consumption.

weidmueller / ie-sw-pl09mt-5gc-4gt_firmware+39
Network
Published Dec 6, 2019
CVE-2019-16672
CRITICAL9.8

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.

weidmueller / ie-sw-pl09m-5gc-4gt_firmware+39
Network
Published Dec 6, 2019
CVE-2019-16673
MEDIUM6.5

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device.

weidmueller / ie-sw-pl09m-5gc-4gt_firmware+39
Network
Published Dec 6, 2019
CVE-2019-16674
CRITICAL9.8

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin password compromise when captured on the network.

weidmueller / ie-sw-pl09m-5gc-4gt_firmware+39
Network
Published Dec 6, 2019
CVE-2019-16670
CRITICAL9.8

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.

weidmueller / ie-sw-pl09m-5gc-4gt_firmware+39
Network
Published Dec 6, 2019