Vulnerabilities & Exploits · Web App Attack

Request Smuggling Lets Attackers Take Over Siemens Data Managers

A web request boundary flaw in the SENTRON 7KT PAC1261 Data Manager can break past the device’s normal access controls. If the web server is exposed, an attacker can steal authorization tokens and use them to gain administrative control, so this is not just a nuisance parsing bug.

CISA says versions before 2.1.0 are affected by CVE-2025-22871. Siemens has released v2.1.0, and the advisory applies to the SENTRON 7KT PAC1261 Data Manager used in energy environments worldwide.

The risk is a device takeover path that starts at the web layer and ends at admin rights. That makes the exposed management interface the real trust boundary, not the login page alone.

1 source · May 14

CVE-2025-22871

NVD KEV

CVSS 9.1 CRITICAL: the net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. EPSS 0.8% (55th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-14

Every edition of this story: Request Smuggling Lets Attackers Take Over Siemens Data Managers

More from today