CRITICAL🇵🇱 Wersja polska

CVE-2025-5598

CVSS 9.2v4.0pub. 2025-06-04upd. 2026-04-15

Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.

🤖 AI Analysis
How it works

The vulnerability results from improper file path handling (CWE-35 — path traversal), which allows an attacker to escape the allowed directory by manipulating file references containing sequences such as '../'. The attack does not require authentication, user interaction, or special network conditions — network access to the vulnerable device is sufficient. As a result, it is possible to read embedded sensitive data stored in the system.

Impact

An attacker can gain access to sensitive data stored on the device without authentication, and in case of data breach from related systems — consequences may also include external environments.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. It is also recommended to restrict network access to the device only to trusted hosts and to monitor unauthorized access attempts to system resources.

Who is affected

WF Steuerungstechnik GmbH airleader MASTER version 3.0046

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References