CVE-2026-41125
KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access. KACO new energy GmbH has released new versions for several affected products and recommends to update to the latest versions. KACO new energy GmbH is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens KACO Blueplanet Inverters are affected: blueplanet 100 NX3 M8 vers:all/* blueplanet 100 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 105 TL3 vers:all/* blueplanet 105 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 110 TL3 vers:all/* blueplanet 125 NX3 M11 vers:all/* blueplanet 125 TL3 vers:all/* blueplanet 125 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 137 TL3 vers:all/* blueplanet 150 TL3 vers:all/* blueplanet 150 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 155 TL3 vers:all/* blueplanet 155 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 165 TL3 vers:all/* blueplanet 165 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 25.0 NX3-33.0 NX3 vers:all/* blueplanet 3.0 NX3-20.0 NX3 vers:all/* blueplanet 3.0 TL3-60.0 TL3 vers:all/* blueplanet 3.0-5.0 NX1 vers:all/* blueplanet 360 NX3 M6 vers:all/* blueplanet 50.0 NX3-60.0 NX3 vers:all/* blueplanet 87.0 TL3 vers:all/* blueplanet 87.0 TL3 GEN2 vers:all/*, vers:intdot/blueplanet 92.0 TL3 vers:all/* blueplanet 92.0 TL3 GEN2 vers:all/*, vers:intdot/blueplanet gridsafe 110 TL3-S vers:intdot/blueplanet gridsafe 137 TL3-S vers:intdot/blueplanet gridsafe 92.0 TL3-S vers:all/*, vers:intdot/blueplanet hybrid 10.0 TL3 vers:all/* blueplanet hybrid 6.0 NH3-12.0 NH3 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 8.3 Siemens Siemens KACO Blueplanet Inverters Use of Hard-coded Cryptographic Key, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.03% · 7.3th percentile
Risk Scores
Timeline
- May 12, 2026 CVE Published
- May 12, 2026 PoC Published
- May 12, 2026 CVE Updated
- May 13, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-02 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-160-02.json advisory
- https://www.cve.org/CVERecord?id=CVE-2025-40946 technical
- https://kaco-newenergy.com/service/mykacocom-customer-portal technical
- https://cwe.mitre.org/data/definitions/321.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H technical
- https://www.cve.org/CVERecord?id=CVE-2026-41125 technical
- https://cwe.mitre.org/data/definitions/89.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H technical