3onedata Modbus Gateway Root Command Injection Flaw
An authenticated command injection bug in 3onedata GW1101-1D(RS-485)-TB-P modbus gateways lets attackers run root shell commands via the diagnosis tool's IP field.
CERT Polska coordinated the disclosure of CVE-2025-13605, a vulnerability affecting 3onedata's GW1101-1D(RS-485)-TB-P Modbus gateway (hardware version V2.2.0). The flaw resides in the device's built-in diagnosis test tools, where an authenticated user can inject arbitrary shell commands through the 'IP address' input field, resulting in command execution with root privileges.
Because the affected device functions as an industrial Modbus-to-Ethernet gateway, exploitation could allow an attacker with valid credentials to pivot from the management interface into full control of the underlying OS, potentially enabling further lateral movement into connected OT/industrial networks. The vendor has released firmware version 3.0.59B2024080600R4353 to remediate the issue, and operators of this device should apply the update promptly.
No evidence of active exploitation was reported; the vulnerability was responsibly disclosed by researchers Jarosław Wawiórko and Łukasz Rybak through CERT Polska's coordinated vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-13605
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free