CVE-2025-60038 is a high-severity vulnerability in Rexroth IndraWorks, allowing remote code execution (RCE) through the deserialization of malicious data. An attacker can achieve complete system compromise if a user opens a specially crafted file. The CVSS score is 8.8 (HIGH), indicating a network-based attack with low complexity but requiring user interaction. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15v24CPE matchmatch criteria | cpe:2.3:a:bosch:rexroth_indraworks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026Vulnerabilities in Rexroth IndraWorks
Feb 13, 2026