CVE-2025-60037 is a high-severity remote code execution (RCE) vulnerability affecting Rexroth IndraWorks, allowing an attacker to execute arbitrary code by tricking a user into opening a specially crafted file containing malicious serialized data. This vulnerability has a CVSS score of 8.8 (HIGH) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, despite requiring user interaction. Currently, there is no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15v24CPE matchmatch criteria | cpe:2.3:a:bosch:rexroth_indraworks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026