# 3onedata GW1101-1D gateway command injection enables root execution

Published: 2026-05-04 · Severity: high · Sectors: infrastructure, energy, manufacturing
Canonical: https://vorant.io/reports/2afb5a67-84b7-4c92-a4b2-c231e3a139f1/3onedata-gw1101-1d-gateway-command-injection-enables-root-execution

> 3onedata GW1101-1D modbus gateway contains authenticated command injection vulnerability (CVE-2025-13605) allowing root-level code execution via diagnosis tool IP field, patched in firmware 3.0.59B2024080600R4353.

CERT Polska coordinated disclosure of CVE-2025-13605, a command injection vulnerability affecting 3onedata GW1101-1D(RS-485)-TB-P modbus gateway devices running hardware version V2.2.0. The flaw allows authenticated users to execute arbitrary shell commands with root privileges by injecting malicious payloads into the IP address field of the device's diagnosis test tools. This vulnerability impacts industrial environments where modbus gateways are commonly deployed for SCADA and ICS communications.

The vendor has released firmware version 3.0.59B2024080600R4353 to address the issue. Organizations using affected 3onedata modbus gateways should prioritize patching, as authenticated access combined with root-level command execution presents a significant risk in operational technology environments. The vulnerability was responsibly reported by Jarosław Wawiórko and Łukasz Rybak through CERT Polska's coordinated vulnerability disclosure program.

## Mentioned in this report

- Vulnerabilities: CVE-2025-13605

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-13605

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2afb5a67-84b7-4c92-a4b2-c231e3a139f1/3onedata-gw1101-1d-gateway-command-injection-enables-root-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
