CVE-2026-41125

Privilege escalation via unneutralized SQL input

Published May 12, 2026 · Updated May 12, 2026

SQL injection in the KACO Meteor server on affected blueplanet inverters allows remote authenticated users to elevate privileges. Siemens states that the server fails to neutralize special SQL elements, but it does not identify the affected endpoint, query, or parameter. Exploitation requires an authorized account, adjacent-network access, and high complexity; successful injection can alter privileges and affect device data or service.

CVSS severity6.0
Medium
EPSS probability0.15%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

SQL injection in the KACO Meteor server on affected blueplanet inverters allows remote authenticated users to elevate privileges. Siemens states that the server fails to neutralize special SQL elements, but it does not identify the affected endpoint, query, or parameter. Exploitation requires an authorized account, adjacent-network access, and high complexity; successful injection can alter privileges and affect device data or service.

The record

CVE
CVE-2026-41125
Published
May 12, 2026
Updated
May 12, 2026
Vendor
KACO new energy
Product
blueplanet gridsave 110 TL3-S
Classifications
CWE-89, T0866
Attack vector
adjacent
Privileges
authenticated

Timeline

How it unfolded

  1. May 12, 2026CVE publishedPublication date reported by the CVE source.
  2. May 12, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <*

What conditions does exploitation require?

Attack vectoradjacent
Required privilegesauthenticated

What is affected?

KACO new energy · blueplanet gridsave 110 TL3-Sversion=0 <*
Siemens · blueplanet 150 TL3version=0 <*
Siemens · blueplanet 92.0 TL3 GEN2version=0 <*
Siemens · blueplanet 165 TL3version=0 <*
Siemens · blueplanet 155 TL3version=0 <*
KACO new energy · blueplanet 100 TL3 GEN2version=0 <*
Siemens · blueplanet gridsave 137 TL3-Sversion=0 <*
Siemens · blueplanet 87.0 TL3version=0 <*
Siemens · blueplanet 137 TL3version=0 <*
Siemens · blueplanet 110 TL3version=0 <*
Siemens · blueplanet 87.0 TL3 GEN2version=0 <*
Siemens · blueplanet 155 TL3 GEN2version=0 <*
Siemens · blueplanet 150 TL3 GEN2version=0 <*
Siemens · blueplanet 105 TL3version=0 <*
Siemens · blueplanet 100 NX3 M8version=0 <*
Siemens · blueplanet 125 TL3version=0 <*
Siemens · blueplanet 92.0 TL3version=0 <*
Siemens · blueplanet 165 TL3 GEN2version=0 <*
Siemens · blueplanet gridsave 92.0 TL3-Sversion=0 <*
Siemens · blueplanet 105 TL3 GEN2version=0 <*
Siemens · blueplanet 125 TL3 GEN2version=0 <*
Siemens · blueplanet 125 NX3 M10version=0 <*

Published CVSS scores

5.9Siemens ProductCERTCVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
6.0Siemens ProductCERTCVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 9, 2026Sep 15, 2026
Latest reporting daySep 15, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectoradjacent
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
T0866Exploitation of Remote Services

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo