SYS::ONLINE
Wasteland.
Briefs1855
Issues23
SinceFeb 2026
LIVE
CVE · Critical CVE-2026-58115 2026-08-11

Siemens SIMATIC IoT2050 Advanced: Unauthenticated Node-RED RCE (CVE-2026-58115)

"Siemens has disclosed a maximum-severity flaw (CVSS 10.0) in SIMATIC IoT2050 Advanced gateways, where the Node-RED HTTP interface enforces no authentication and lets a remote attacker execute arbitrary code with maximum…"

Siemens has disclosed a maximum-severity flaw (CVSS 10.0) in SIMATIC IoT2050 Advanced gateways, where the Node-RED HTTP interface enforces no authentication and lets a remote attacker execute arbitrary code with maximum privileges.

What Is It

CVE-2026-58115 is a missing authentication vulnerability (CWE-306) in SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. Affected devices do not enforce authentication on the Node-RED HTTP interface, which exposes programming nodes capable of executing system commands on the server. An unauthenticated remote attacker can reach that interface and create malicious flows to execute arbitrary code on the underlying server with maximum privileges.

Why It Matters

Siemens ProductCERT rates this at CVSS 3.1 base score 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, with an exploitability subscore of 3.9; the maximum. The CVSS 4.0 assessment is also 10.0 CRITICAL, with high confidentiality, integrity, and availability impact both to the vulnerable system and to downstream subsequent systems.

There is no authentication barrier, no privilege requirement, and no user interaction: an attacker who can reach the Node-RED HTTP interface over the network gets code execution at maximum privilege. The changed scope in the CVSS 3.1 vector reflects that compromise does not stop at the Node-RED process.

Neither Siemens ProductCERT nor NVD reports exploitation of this vulnerability as of publication.

What's Vulnerable

Devices without Node-RED installed are outside the stated affected configuration.

Patch Status

Siemens has fixed the issue in V4.3.4.1 and later; the affected version range is explicitly bounded at versions below V4.3.4.1. Operators of SIMATIC IoT2050 Advanced devices with Node-RED installed should update to V4.3.4.1 or later and consult Siemens Security Advisory SSA-834709 for the full remediation guidance.

The record was published 2026-08-11 and currently carries NVD status "Received," meaning NVD analysis is not yet complete.

Sources