VORANT. Threat Intelligence Sign in Get the full feed

3onedata Modbus Gateway Root Command Injection Flaw

medium vulnerability infrastructuremanufacturing

An authenticated command injection bug in 3onedata GW1101-1D(RS-485)-TB-P modbus gateways lets attackers run root shell commands via the diagnosis tool's IP field.

CERT Polska coordinated the disclosure of CVE-2025-13605, a vulnerability affecting 3onedata's GW1101-1D(RS-485)-TB-P Modbus gateway (hardware version V2.2.0). The flaw resides in the device's built-in diagnosis test tools, where an authenticated user can inject arbitrary shell commands through the 'IP address' input field, resulting in command execution with root privileges.

Because the affected device functions as an industrial Modbus-to-Ethernet gateway, exploitation could allow an attacker with valid credentials to pivot from the management interface into full control of the underlying OS, potentially enabling further lateral movement into connected OT/industrial networks. The vendor has released firmware version 3.0.59B2024080600R4353 to remediate the issue, and operators of this device should apply the update promptly.

No evidence of active exploitation was reported; the vulnerability was responsibly disclosed by researchers Jarosław Wawiórko and Łukasz Rybak through CERT Polska's coordinated vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2025-13605

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-13605

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free