VORANT. Threat Intelligence Sign in Get the full feed

3onedata GW1101-1D gateway command injection enables root execution

high vulnerability infrastructureenergymanufacturing

3onedata GW1101-1D modbus gateway contains authenticated command injection vulnerability (CVE-2025-13605) allowing root-level code execution via diagnosis tool IP field, patched in firmware 3.0.59B2024080600R4353.

CERT Polska coordinated disclosure of CVE-2025-13605, a command injection vulnerability affecting 3onedata GW1101-1D(RS-485)-TB-P modbus gateway devices running hardware version V2.2.0. The flaw allows authenticated users to execute arbitrary shell commands with root privileges by injecting malicious payloads into the IP address field of the device's diagnosis test tools. This vulnerability impacts industrial environments where modbus gateways are commonly deployed for SCADA and ICS communications.

The vendor has released firmware version 3.0.59B2024080600R4353 to address the issue. Organizations using affected 3onedata modbus gateways should prioritize patching, as authenticated access combined with root-level command execution presents a significant risk in operational technology environments. The vulnerability was responsibly reported by Jarosław Wawiórko and Łukasz Rybak through CERT Polska's coordinated vulnerability disclosure program.

Mentioned in this report

Vulnerabilities CVE-2025-13605

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-13605

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free