Critical Zero-Day in Siemens SIMATIC IoT2050 Advanced Enables Unauthenticated Remote Code Execution
Overview
CVE-2026-58115 is a CVSS 10.0 critical vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED, enabling unauthenticated attackers to execute arbitrary code as root. This vulnerability directly threatens operational technology (OT) environments in industrial and enterprise networks.
Technical Analysis
The flaw stems from a complete absence of authentication enforcement for the Node-RED HTTP management interface (port 1880). Attackers can craft malicious flow JSON payloads leveraging Node-RED's exec node functionality to trigger system command execution. Exploitation requires only a simple POST request to the /flows endpoint, bypassing all security controls to establish persistent backdoors or disrupt ICS operations.
Enterprise & DIB Impact
Defense Industrial Base (DIB) providers using SIMATIC IoT2050 Advanced face immediate risk of full device compromise, including exfiltration of industrial control logic and credentials. The vulnerability's CVSS-10 rating and trivial exploitability make it a high-priority target for ransomware and nation-state actors seeking OT/IT convergence access points.
Recommended Actions
- Apply Siemens' Industrial OS V4.3.4.1 firmware update to affected devices immediately
- Implement strict network segmentation to isolate IoT2050 Advanced devices from public/internet-facing networks
- Configure Node-RED authentication via ui-base settings even if not required by default
- Deploy signature-based IDS/IPS rules blocking anomalous POST requests to port 1880
- Conduct physical security audits to identify IoT2050 Advanced devices with open HTTP interfaces at industrial facilities
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →