What is CVE-2026-58115?
Unauthenticated access to the Node-RED HTTP interface is possible on affected SIMATIC IoT2050 Advanced devices, allowing potential manipulation of programming nodes. Admins should update to firmware version V4.3.4.1 or later to enforce authentication.
Azərbaycanca: SIMATIC IoT2050 Advanced cihazlarında Node-RED HTTP interfeysində autentifikasiya tətbiq edilmədiyi üçün uzaqdan icazəsiz giriş mümkündür. Bu boşluq, təsirlənmiş qurğularda Node-RED node-larına müdaxiləyə yol aça bilər. İdarəçilərə dərhal cihaz proqram təminatını V4.3.4.1 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which devices are affected by CVE-2026-58115?
This vulnerability affects SIMATIC IoT2050 Advanced devices.
Which firmware version is needed to mitigate CVE-2026-58115?
Administrators are advised to update the device firmware to version V4.3.4.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.