Request Smuggling Lets Attackers Take Over Siemens Data Managers
A web request boundary flaw in the SENTRON 7KT PAC1261 Data Manager can break past the device’s normal access controls. If the web server is exposed, an attacker can steal authorization tokens and use them to gain administrative control, so this is not just a nuisance parsing bug.
CISA says versions before 2.1.0 are affected by CVE-2025-22871. Siemens has released v2.1.0, and the advisory applies to the SENTRON 7KT PAC1261 Data Manager used in energy environments worldwide.
The risk is a device takeover path that starts at the web layer and ends at admin rights. That makes the exposed management interface the real trust boundary, not the login page alone.