CVE-2025-60036 is a critical remote code execution (RCE) vulnerability affecting the UA.Testclient utility within Rexroth IndraWorks, specifically versions prior to 15V24. This flaw allows an attacker to execute arbitrary code on a user's system by tricking them into opening a specially crafted file containing malicious serialized data. The vulnerability carries a CVSS score of 8.8 (High), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, though it requires user interaction. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15v24CPE matchmatch criteria | cpe:2.3:a:bosch:rexroth_indraworks:*:*:*:*:*:*:*:* | ||
< 2.9.0CPE matchmatch criteria | cpe:2.3:a:bosch:rexroth_ua.testclient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026