CISA says Siemens fixed a missing-authentication flaw in SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed, tracked as CVE-2026-58115. On affected 6ES7647-0BA00-1YA2 systems, an unauthenticated remote attacker could create malicious Node-RED flows and run code with maximum privileges.
The problem is the Node-RED HTTP interface itself: it accepts programming requests without checking who is calling. That means an attacker can submit automation logic as if they were an operator, and those flows can execute system commands on the device.
For operators who use IoT2050 as part of industrial control or edge automation, the exposure sits at the programming layer, not just the network perimeter. Once that interface is reachable, the device can be reprogrammed with privileged logic until it is updated or Node-RED is otherwise removed or hardened.