CVE-2025-48466
Modbus Command Injection without Authentication
- Published
- Jun 24, 2025
- Updated
- Jun 25, 2025
- Assigning CNA
- CSA
- Evidence observed
- Aug 4, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HLow · next 30 days
- Percentile
- 43.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.
Sources
1Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.