TL;DR
CERT@VDE has disclosed CVE-2026-94293, a critical AAS edge client vulnerability in Murrelektronik’s aas-edge-client. The flaw scores 9.8 on CVSS 3.1 and lets anyone on the network read and change device data without logging in. Murrelektronik will not release a fix and tells users to remove the software.
- CVE: CVE-2026-94293
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Murrelektronik Software AAS Edge Client all versions
- Affected: 0.0.0
- Impact: Missing authentication for critical function in the aas-edge-client REST API
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysWhy It Matters
The aas-edge-client is a reference app for the Asset Administration Shell (AAS), a digital twin standard in Industry 4.0. Murrelektronik built it for the LNI 4.0 testbed demonstrator. According to the advisory, it “was never intended for productive use and is no longer maintained.”
However, the code was public on GitHub, so copies may still run in labs or plants. So far, no exploitation in the wild or public proof-of-concept has been confirmed.
How the Attack Works
The app’s REST API listens on TCP port 18000 on every network interface. Moreover, it “requires no authentication and accepts cross-origin requests from any origin.” As a result, an attacker can read all exposed data and change AAS submodel data.
The open cross-origin setting widens the risk. A malicious web page opened by a user on the same network could also reach the device. Worse, the edge client forwards changed data to the central AAS server. “Systems consuming that server may receive manipulated device information,” CERT@VDE warns.
Affected Versions
All versions of the aas-edge-client are affected. The flaw is tracked as CWE-306, missing authentication for a critical function.
Patch and Mitigation Steps
No patch is coming. Instead, Murrelektronik says to “discontinue the use of the aas-edge-client and remove any existing deployments as well as copies of the source code and container image.” The company has also archived the repository and made its GitHub organisation private.
Teams that find this AAS edge client vulnerability in their environment should also check what the central AAS server received.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!