CVE-2026-41125

MEDIUM

View CSAF Summary KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthoriz...

Affects 0 products across 2 vendors.

BCS4.22
CVSS 3.16.0
CVSS v45.9
EPSS0.2%
Percentile5th
PatchUnknown
CVSS Vector — Plain English Exploitable from adjacent network, high complexity, high privileges required, no user interaction needed, impact contained to the vulnerable component, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "A vulnerability has been identified in multiple versions of blueplanet devices, including NX3 M8, TL3 GEN2, TL3, TL3 GEN2, 105 TL3, 105 TL3 GEN2, 110 TL3, 125 NX3 M11, 125 TL3, 125 TL3 GEN2, 137 TL3, and 150 TL3. This vulnerability could allow an attacker to exploit the system, potentially leading to unauthorized access or other malicious activities.", "attack_vector_detail": "The vulnerability is likely to be exploited through a specific protocol or service that is exposed to the network. Given the CVSS score of 6.0, it is considered a moderate risk, suggesting that the attack vector is not trivial but requires some level of access or knowledge.", "affected_components": [ "blueplanet 100 NX3 M8 (All versions)", "blueplanet 100 TL3 GEN2 (All versions)", "blueplanet 105 TL3 (All versions)", "blueplanet 105 TL3 GEN

BSID: BS-2026-GLOBAL-152413-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-41125?
{ "executive_summary": "A vulnerability has been identified in multiple versions of blueplanet devices, including NX3 M8, TL3 GEN2, TL3, TL3 GEN2, 105 TL3, 105 TL3 GEN2, 110 TL3, 125 NX3 M11, 125 TL3, 125 TL3 GEN2, 137 TL3, and 150 TL3. This vulnerability could allow an attacker to exploit the system, potentially leading to unauthorized access or other malicious activities.", "attack_vector_detail": "The vulnerability is likely to be exploited through a specific protocol or service that is e
What is the CVSS score for CVE-2026-41125?
CVE-2026-41125 has CVSS 6.0 (Medium). Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H. EPSS: 0.2%.
Is CVE-2026-41125 actively exploited?
No confirmed active exploitation of CVE-2026-41125 as of 2026-06-10.
How do I remediate CVE-2026-41125?
Priority: LOW.
What systems are affected by CVE-2026-41125?
CVE-2026-41125 affects: Fujitsu-Siemens, Siemens.
Vulnerability Details
CVE IDCVE-2026-41125
BSIDBS-2026-GLOBAL-152413-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
Published2026-06-09
Last Modified2026-06-09
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access. KACO new energy GmbH has released new versions for several affected products and recommends to update to the latest versions. KACO new energy GmbH is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions o

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M11 (All versions), blueplanet 125 TL3 (All versions), blueplanet 125 TL3 GEN2 (All versions), blueplanet 137 TL3 (All versions), blueplanet 150 TL3 (All versions), blueplanet 150 TL3 GEN2 (All versions), blueplanet 155 TL3 (All versions), blueplanet 155 CVSS vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Fujitsu-Siemens —
Siemens —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 46 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash334b6b65a92531cb065119535b4ea5ab4d6917104d207afb42c6cb580baa971cb207e1490b62aaee09258030000513e7b5e8a6b6a5fdec2060e9131b94a5e587
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →