Weidmueller manufactures industrial automation and networking devices, particularly wireless access points and connectivity appliances deployed in manufacturing and process-control environments where uptime and physical security are critical. The vendor's vulnerability profile, while modestly represented in overall volume, ranks among the more prominent in the industrial networking space and skews toward critical-severity outcomes across its product line. Exposure concentrates in its wireless access-point and industrial Ethernet products—including its IE-WL series across regional variants—and recurs through OS command injection, hard-coded and insufficiently protected credentials, and classic buffer overflows that reflect the embedded firmware and legacy authentication postures common in operational technology. These weakness classes are particularly consequential in industrial settings, where remote code execution through command injection or credential compromise can disrupt production and compromise physical systems. Defenders managing industrial sites should prioritize inventory and segmentation of these devices and monitor for firmware updates closely; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weidmueller over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16672CRITICAL An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials dat | Dec 6, 2019 | 9.8 | 30 | NO | NO |
CVE-2021-20999CRITICAL In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces | May 13, 2021 | 9.8 | 28 | NO | NO |
CVE-2019-16670CRITICAL An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechan | Dec 6, 2019 | 9.8 | 27 | NO | NO |
CVE-2021-33538HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially c | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33535HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted ti | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33533HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip para | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33532HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic scrip | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33530HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A spe | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33528HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selec | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33537HIGH In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A speciall | Jun 25, 2021 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weidmueller.
Media articles that mention a CVE ID that affects a product developed by Weidmueller — matched by CVE ID, not by vendor name.