CVE-2025-41709Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-1003-11
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-103
Disclosure2General1
2026-03-111
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical flaws (CVE-2025-41709) in Janitza and Weidmueller energy meters allow remote code execution and full system takeover. Update to firmware 3.14 now. #Janitza #Weidmueller #CVE #CyberSecurity #ICSSecurity #RCE #CommandInjection #EnergyGrid #InfoSec https://securityonline.info/critical-rce-vulnerabilities-uncovered-in-janitza-and-weidmueller-energy-meters/

    Post summary

    CVE‑2025‑41709 enables remote code execution in Janitza and Weidmueller energy meters; users are urged to update to firmware 3.14 to address the flaw.

    00011270
    10.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41709 [PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR] https://www.cve.org/CVERecord?id=CVE-2025-41709

    Post summary

    The text is a placeholder-style CVE announcement that lists component, platform, and attack vector but lacks concrete technical details, exploitation evidence, or mitigation guidance.

    00010181
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2025-41709: CRITICAL] [PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR]#cve,CVE-2025-41709,#cybersecurity https://cvefind.com/CVE-2025-41709

    Post summary

    The post references CVE-2025-41709 but only contains placeholder text with no substantive details about the vulnerability, exploitation, or mitigation.

    0000071
    601 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-41709: Comm... Unauthenticated RCE via Modbus protocol on industrial power analyzers - critical infrastructure just became a honeypot for APTs. #ICS #Modbus #RCE. https://zerodaysignal.com/vulnerability/CVE-2025-41709 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces the discovery of CVE-2025-41709, detailing an unauthenticated RCE vulnerability via Modbus on industrial power analyzers, and provides a link for further information.

    00000142
    142 followersView on X

Explore more