CVE-2025-13605
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test tools. This issue has been resolved in firmware version 3.0.59B2024080600R4353
Published:May 4, 2026
Last Modified:May 4, 2026
EPS:May 4, 2026
EPSS Score:
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
3onedata
Product
Gw1101-1d(rs-485)-tb-p
3onedata
Gw1101-1d(rs-485)-tb-p
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
