CVE-2025-40946

HIGH

View CSAF Summary KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthoriz...

Affects 0 products across 2 vendors.

BCS5.6
CVSS 3.18.3
CVSS v47.2
EPSS0.2%
Percentile8th
PatchUnknown
CVSS Vector — Plain English Exploitable from adjacent network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-321: CWE-321
◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "A critical vulnerability has been identified in multiple versions of blueplanet devices, including NX3 M8, TL3 GEN2, TL3, TL3 GEN2, and TL3 M11 series, which could allow an attacker to execute arbitrary code with system-level privileges.", "attack_vector_detail": "The vulnerability is likely due to improper validation of input data, which could be exploited by sending specially crafted packets to the affected devices. This could lead to remote code execution, unauthorized access, and potential device compromise.", "affected_components": [ "blueplanet 100 NX3 M8 (All versions)", "blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9)", "blueplanet 105 TL3 (All versions)", "blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9)", "blueplanet 110 TL3 (All versions)", "blueplanet 125 NX3 M11 (All versions)", "blueplanet 125 TL3 (All versions)", "blueplanet 12

BSID: BS-2026-GLOBAL-259437-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-40946?
{ "executive_summary": "A critical vulnerability has been identified in multiple versions of blueplanet devices, including NX3 M8, TL3 GEN2, TL3, TL3 GEN2, and TL3 M11 series, which could allow an attacker to execute arbitrary code with system-level privileges.", "attack_vector_detail": "The vulnerability is likely due to improper validation of input data, which could be exploited by sending specially crafted packets to the affected devices. This could lead to remote code execution, unauthor
What is the CVSS score for CVE-2025-40946?
CVE-2025-40946 has CVSS 8.3 (High). Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H. EPSS: 0.2%.
Is CVE-2025-40946 actively exploited?
No confirmed active exploitation of CVE-2025-40946 as of 2026-06-10.
How do I remediate CVE-2025-40946?
Apply vendor patches for CVE-2025-40946. Monitor Fujitsu-Siemens, Siemens advisories.
What systems are affected by CVE-2025-40946?
CVE-2025-40946 affects: Fujitsu-Siemens, Siemens.
Vulnerability Details
CVE IDCVE-2025-40946
BSIDBS-2026-GLOBAL-259437-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Published2026-06-09
Last Modified2026-06-09
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access. KACO new energy GmbH has released new versions for several affected products and recommends to update to the latest versions. KACO new energy GmbH is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions o

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Fujitsu-Siemens &mdash;
Siemens &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 46 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
Enriched At2026-05-25
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →