CVE-2025-22871

CRITICAL

View CSAF Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to re...

Affects 0 products across 2 vendors.

BCS7.03
CVSS 3.19.1
EPSS0.8%
Percentile52th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
◆ SAGE Intelligence — CITED Relevance Research Team

The Siemens SENTRON 7KT PAC1261 Data Manager before V2.1.0 is vulnerable to a request smuggling attack, which can lead to unauthorized access and administrative control over the device. Siemens recommends updating to the latest version to mitigate this risk.

BSID: BS-2026-GLOBAL-296568-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-22871?
The Siemens SENTRON 7KT PAC1261 Data Manager before V2.1.0 is vulnerable to a request smuggling attack, which can lead to unauthorized access and administrative control over the device. Siemens recommends updating to the latest version to mitigate this risk.
What is the CVSS score for CVE-2025-22871?
CVE-2025-22871 has CVSS 9.1 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. EPSS: 0.8%.
Is CVE-2025-22871 actively exploited?
No confirmed active exploitation of CVE-2025-22871 as of 2026-05-30.
How do I remediate CVE-2025-22871?
Priority: MEDIUM.
What systems are affected by CVE-2025-22871?
CVE-2025-22871 affects: Fujitsu-Siemens, Siemens.
What NERC-CIP standard applies to CVE-2025-22871?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to the device, which could compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2025-22871?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability in the web server that could allow an attacker to gain unauthorized access, which is a critical security concern for industrial control systems.
Vulnerability Details
CVE IDCVE-2025-22871
BSIDBS-2026-GLOBAL-296568-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Published2026-05-14
Last Modified2026-05-14
ICS Relevance55%
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain administrative control over the device. Siemens has released a new version for SENTRON 7KT PAC1261 Data Manager and recommends to update to the latest version. The following versions of Siemens SENTRON 7KT PAC1261 Data Manager are affected: SENTRON 7

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the web server component of the SENTRON 7KT PAC1261 Data Manager, specifically in the Go Project's net/http package. An attacker can exploit this by sending specially crafted HTTP requests that bypass the intended security controls, allowing them to retrieve authorization tokens and gain administrative control over the device.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Fujitsu-Siemens —
Siemens —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and output encoding on the web server to prevent request smuggling attacks. Ensure that all HTTP headers and request bodies are properly sanitized.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to the device, which could compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability in the web server that could allow an attacker to gain unauthorized access, which is a critical security concern for industrial control systems.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash9a90200b19df0ce43babaf5fc06901dfafbcd6494bac2a5e9e0e7560c174f551dc9202710842fce4fe33d3fd71b540c2cdd192c20e06e10d12db3ad8c394277b
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.1 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →