RandoriSec
Responsible disclosure
TL; DR During a penetration test engagement, RandoriSec came across a Siemens OZW772 [0] device exposed on the Internet and decided to study its custom HTTP component. Two critical vulnerabilities were discovered by our team [1], affecting old versions of the firmware:
(CVE-2025-26389 – CVSS 3.1 = 10): Pre-authentication remote code execution (RCE) with root privileges (OS command injection) – affected versions: < V8.0 (CVE-2025-26390 – CVSS 3.1 = 9.8): Authentication bypass (SQL injection) – affected versions: < V6.