3onedata GW1101-1D gateway command injection enables root execution
3onedata GW1101-1D modbus gateway contains authenticated command injection vulnerability (CVE-2025-13605) allowing root-level code execution via diagnosis tool IP field, patched in firmware 3.0.59B2024080600R4353.
CERT Polska coordinated disclosure of CVE-2025-13605, a command injection vulnerability affecting 3onedata GW1101-1D(RS-485)-TB-P modbus gateway devices running hardware version V2.2.0. The flaw allows authenticated users to execute arbitrary shell commands with root privileges by injecting malicious payloads into the IP address field of the device's diagnosis test tools. This vulnerability impacts industrial environments where modbus gateways are commonly deployed for SCADA and ICS communications.
The vendor has released firmware version 3.0.59B2024080600R4353 to address the issue. Organizations using affected 3onedata modbus gateways should prioritize patching, as authenticated access combined with root-level command execution presents a significant risk in operational technology environments. The vulnerability was responsibly reported by Jarosław Wawiórko and Łukasz Rybak through CERT Polska's coordinated vulnerability disclosure program.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-13605
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free