Authenticated Users Can Take Root on 3onedata Gateways

A valid login is enough to turn this gateway into a root shell. The weak point is a diagnostic field that should only accept an IP address, so credential compromise alone can become full device takeover. CERT Polska says CVE-2025-13605 affects 3onedata GW1101-1D(RS-485)-TB-P gateways on hardware V2.2.0. The flaw lets authenticated users run arbitrary shell commands as root, and firmware 3.0.59B2024080600R4353 fixes it. That makes the device a high-value pivot point in networks that trust it for industrial connectivity. If an attacker gets any working account, the gateway itself becomes the privilege boundary they can cross.

Part of the PlainSec briefing for 2026-05-04

Sources