CVE-2025-22871
View CSAF Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to re...
Affects 0 products across 2 vendors.
The Siemens SENTRON 7KT PAC1261 Data Manager before V2.1.0 is vulnerable to a request smuggling attack, which can lead to unauthorized access and administrative control over the device. Siemens recommends updating to the latest version to mitigate this risk.
BSID: BS-2026-GLOBAL-296568-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-22871?
What is the CVSS score for CVE-2025-22871?
Is CVE-2025-22871 actively exploited?
How do I remediate CVE-2025-22871?
What systems are affected by CVE-2025-22871?
What NERC-CIP standard applies to CVE-2025-22871?
What IEC 62443 requirement maps to CVE-2025-22871?
| CVE ID | CVE-2025-22871 |
|---|---|
| BSID | BS-2026-GLOBAL-296568-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| Published | 2026-05-14 |
| Last Modified | 2026-05-14 |
| ICS Relevance | 55% |
| Verticals | |
| Source | NVD |
View CSAF Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain administrative control over the device. Siemens has released a new version for SENTRON 7KT PAC1261 Data Manager and recommends to update to the latest version. The following versions of Siemens SENTRON 7KT PAC1261 Data Manager are affected: SENTRON 7
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the web server component of the SENTRON 7KT PAC1261 Data Manager, specifically in the Go Project's net/http package. An attacker can exploit this by sending specially crafted HTTP requests that bypass the intended security controls, allowing them to retrieve authorization tokens and gain administrative control over the device.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation and output encoding on the web server to prevent request smuggling attacks. Ensure that all HTTP headers and request bodies are properly sanitized.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to the device, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 because it involves a vulnerability in the web server that could allow an attacker to gain unauthorized access, which is a critical security concern for industrial control systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 9a90200b19df0ce43babaf5fc06901dfafbcd6494bac2a5e9e0e7560c174f551dc9202710842fce4fe33d3fd71b540c2cdd192c20e06e10d12db3ad8c394277b |
Critical Severity - Know Your Exposure
A CVSS 9.1 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →