CVE-2025-60037

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the application to deserialize the malicious data, enabling Remote Code Execution (RCE). This can lead to a complete compromise of the system running Rexroth IndraWorks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:bosch:rexroth_indraworks:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:49

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido identificada en Rexroth IndraWorks. Esta falla permite a un atacante ejecutar código arbitrario en el sistema del usuario al analizar un archivo manipulado que contiene datos serializados maliciosos. La explotación requiere interacción del usuario, específicamente la apertura de un archivo especialmente diseñado, lo que luego provoca que la aplicación deserialice los datos maliciosos, habilitando la Ejecución Remota de Código (RCE). Esto puede llevar a un compromiso completo del sistema que ejecuta Rexroth IndraWorks.

24 Feb 2026, 16:02

Type Values Removed Values Added
First Time Bosch rexroth Indraworks
Bosch
References () https://psirt.bosch.com/security-advisories/BOSCH-SA-591522.html - () https://psirt.bosch.com/security-advisories/BOSCH-SA-591522.html - Vendor Advisory
CPE cpe:2.3:a:bosch:rexroth_indraworks:*:*:*:*:*:*:*:*

18 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 14:16

Updated : 2026-06-17 09:49


NVD link : CVE-2025-60037

Mitre link : CVE-2025-60037

CVE.ORG link : CVE-2025-60037


JSON object : View

Products Affected

bosch

  • rexroth_indraworks
CWE
CWE-502

Deserialization of Untrusted Data