Bosch Rexroth's vulnerability footprint is concentrated in its ctrlX HMI web panel line of industrial control interfaces and associated firmware, which serve as operator terminals and integration points in automation environments. The recurring weakness classes—missing authentication for critical functions, hard-coded credentials, cleartext transmission of sensitive data, and improper access control—reflect the legacy design and integration constraints of embedded control-system web interfaces rather than modern security architecture. Defenders managing these devices should inventory affected models and restrict network exposure of the HMI interfaces; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boschrexroth over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46102HIGH The Android Client application, when enrolled to the AppHub server, connects to an MQTT
broker to exchange messages and receive commands to execute on the HMI device.
The protoco | Oct 25, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-41255HIGH The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication
of the | Oct 25, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-45851HIGH The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.
This issue allows an attacker to fo | Oct 25, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-45321HIGH The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip a | Oct 25, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-45220HIGH The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip ad | Oct 25, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-41372HIGH The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to a | Oct 25, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-43488HIGH The vulnerability allows a low privileged (untrusted) application to
modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) pro | Oct 25, 2023 | 7.8 | 21 | NO | NO |
CVE-2023-45844MEDIUM The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access t | Oct 25, 2023 | 6.8 | 20 | NO | NO |
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modif | Oct 25, 2023 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boschrexroth.
Media articles that mention a CVE ID that affects a product developed by Boschrexroth — matched by CVE ID, not by vendor name.