Siemens IoT2050 Node-RED flaw enables RCE
A missing-authentication flaw in Node-RED on Siemens SIMATIC IoT2050 Advanced devices lets unauthenticated attackers run arbitrary code with full privileges.
CISA republished a Siemens ProductCERT advisory (SSA-834709) describing CVE-2026-58115, a missing authentication vulnerability affecting the Node-RED HTTP interface on SIMATIC IoT2050 Advanced devices running versions prior to V4.3.4.1 with Node-RED installed. Because the interface does not enforce authentication, an unauthenticated remote attacker can reach programming nodes capable of executing system commands, allowing them to craft malicious Node-RED flows and achieve arbitrary code execution on the underlying host with maximum privileges.
The affected product, SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2), is deployed worldwide across critical infrastructure sectors including chemical, critical manufacturing, energy, and transportation systems. Siemens has released version V4.3.4.1 to remediate the issue and strongly recommends updating; interim mitigations include hardening the Node-RED installation per vendor guidance or uninstalling Node-RED entirely if not required. CISA also reiterates standard ICS hardening practices: minimizing internet exposure of control system devices, isolating control networks behind firewalls, and using secure remote access methods such as VPNs.
There is no indication in the advisory of active exploitation in the wild; this is a proactive vendor disclosure and patch release. The vulnerability's low complexity (no authentication required, direct path to code execution with maximum privileges) makes it a priority for any operator running affected devices with Node-RED enabled, given the industrial deployment context and potential for significant operational impact if exploited.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free