CVE-2025-60038 PUBLISHED

Assigner: bosch
Reserved: 25.09.2025 Published: 18.02.2026 Updated: 18.02.2026

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the application to deserialize the malicious data, enabling Remote Code Execution (RCE). This can lead to a complete compromise of the system running Rexroth IndraWorks.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Bosch Rexroth
Product IndraWorks
Versions
  • Version all is affected

References

Problem Types