VDE-2025-033 PUBLISHED CVSS 6.5 MEDIUM

The ADS-TEC firewall products IRF1000, IRF2000, and IRF3000 include Eclipse Mosquitto, affected by multiple vulnerabilities. Exploitation requires a compromised upstream MQTT broker, limiting direct device exposure.

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Firmware 2.1.0
DVG-IRF3401
DVG-IRF2200
DVG-IRF2100
DVG-IRF3801
Firmware <6.1.0
DVG-IRF2601
Firmware 6.1.0
DVG-IRF2220
Firmware <2.1.0
DVG-IRF3421
DVG-IRF3821
DVG-IRF1421
DVG-IRF2621
DVG-IRF1401

Timeline

References

Open in Interactive Console →