| Publisher: Weidmueller Interface GmbH & Co. KG | Document category: csaf_security_advisory |
| Initial release date: 2026-02-26T11:00:00.000Z | Engine: Secvisogram 2.5.43 |
| Current release date: 2026-02-26T11:00:00.000Z | Build Date: 2026-02-26T11:00:00.000Z |
| Current version: 1.0.0 | Status: final |
| CVSSv3.1 Base Score: 9.8 | Severity: High |
| Original language: | Language: en-GB |
| Also referred to: VDE-2025-096, WMSA-2600001 | |
An unauthenticated remote attacker can exploit several vulnerabilities in Weidmueller devices Energy Meter 750-24 and Energy Meter 750-230 to ultimately gain full system access and remote code execution.
As a general security measure, Weidmueller strongly recommends to change the default passwords and to minimize the network exposure of products. Limit access to trusted networks by using the appropriate mechanisms.
These vulnerabilities in combination allow an unauthenticated remote attacker to fully compromise the system including remote code execution. Further details on each separate vulnerability can be found under vulnerability details.
It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14.
| Product | Atricle number | Affected Version | Fixed Version |
|---|---|---|---|
| ENERGY METER 750-24 | 2540900000 | <=3.13 | 3.14 |
| ENERGY METER 750-230 | 2540910000 |
An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.
| CWE: | CWE-78:Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
|---|
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| Firmware 3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 |
| Firmware 3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 |
| Firmware <=3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 |
| Firmware <=3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 |
Update to version 3.14
An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.
| CWE: | CWE-798:Use of Hard-coded Credentials |
|---|
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| Firmware 3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N | 6.5 |
| Firmware 3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N | 6.5 |
| Firmware <=3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N | 6.5 |
| Firmware <=3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N | 6.5 |
Update to version 3.14
An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access.
| CWE: | CWE-327:Use of a Broken or Risky Cryptographic Algorithm |
|---|
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| Firmware 3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 5.3 |
| Firmware 3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 5.3 |
| Firmware <=3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 5.3 |
| Firmware <=3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 5.3 |
Update to version 3.14
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.
| CWE: | CWE-732:Incorrect Permission Assignment for Critical Resource |
|---|
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| Firmware 3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 6.5 |
| Firmware 3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 6.5 |
| Firmware <=3.13 installed on ENERGY METER 750-24 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 6.5 |
| Firmware <=3.13 installed on ENERGY METER 750-230 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 6.5 |
Update to version 3.14
Namespace: https://www.weidmueller.com
psirt@weidmueller.com
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1.0.0 | 2026-02-26T11:00:00.000Z | Initial version |
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/