CVE-2025-22871
CVSS 9.1 CRITICAL: the net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. EPSS 0.8% (55th percentile).
Vulnerabilities · 124 days ago
A web request boundary flaw in the SENTRON 7KT PAC1261 Data Manager can break past the device’s normal access controls. If the web server is exposed, an attacker can steal authorization tokens and use them to gain administrative control, so this is not just a nuisance parsing bug.
CISA says versions before 2.1.0 are affected by CVE-2025-22871. Siemens has released v2.1.0, and the advisory applies to the SENTRON 7KT PAC1261 Data Manager used in energy environments worldwide.
The risk is a device takeover path that starts at the web layer and ends at admin rights. That makes the exposed management interface the real trust boundary, not the login page alone.
CVSS 9.1 CRITICAL: the net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. EPSS 0.8% (55th percentile).
1 source covering this story
Siemens SENTRON 7KT PAC1261 Data Manager | CISA
Siemens SENTRON 7KT PAC1261 Data Manager Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain…
Part of the PlainSec briefing for 2026-05-14