securityonline.info 8/3/2026, 2:26:51 AM · external

Critical SQLi Bug in Weidmüller PROCONWEB SCADA Threatens OT

Critical SQLi Bug in Weidmüller PROCONWEB SCADA Threatens OT
CyberSIXT Evidence Panel
Primary Source certvde.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical SQL injection vulnerability, tracked as CVE-2026-16462, has been identified in Weidmueller's PROCON-WEB SCADA software, scoring 9.8 on the CVSS scale. This flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands via an insecure 'GetGridData' endpoint. Affected versions include PROCON-WEB SCADA 1.0.0 to 6.11.2, with the need for immediate patching to version 6.11.3 as there is no confirmed exploitation reported yet.

The potential impact includes unauthorized data access, modification, or deletion, which could disrupt physical processes in industrial and building automation.

View Primary Source Via securityonline.info

Article by CyberSIXT