PT-2026-24183 · Modbus · Modbus

Published

2026-03-10

·

Updated

2026-03-11

·

CVE-2025-41709

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Versions prior to 2025-41709
Description An issue exists that allows an attacker to achieve remote code execution via the Modbus protocol on industrial power analyzers. This poses a significant risk to critical infrastructure, potentially turning it into a target for advanced persistent threats (APTs). The vulnerability is unauthenticated, meaning no login is required to exploit it. The affected component and vendor are not specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-02865
CVE-2025-41709

Affected Products

Modbus