External risk intelligence

SICK TLOC100-100 Unauthenticated API Vulnerability Allows Data Access and Service Disruption.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-59461

The vulnerability affects an industrial device (SICK TLOC100-100) and involves an unauthenticated C++ API. While industrial control system components are typically deployed in isolated or internal environments, they are occasionally exposed to broader networks or the internet in specific industrial IoT or remote monitoring configurations, making reachability possible but not the default or intended design.

Sick Tloc100 100 Firmware

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in certain SICK industrial devices, allowing remote attackers to access or modify sensitive data and disrupt services without authentication. This could potentially impact operational continuity if the affected technology is exposed.

  • Unauthenticated attackers can access or change data.
  • This affects critical industrial devices.
  • Confirm if this technology is in use.

Attack Path

How an attacker could exploit the issue

A remote attacker could exploit this vulnerability by reaching the unauthenticated C++ API over the network. This access allows them to potentially read, write, or disrupt sensitive data and services on the affected device, leading to significant operational impacts.

  • Network access required.
  • Unauthenticated C++ API is triggered.
  • Confidentiality, integrity, and availability impacted.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could remotely access or alter sensitive data and disrupt services on affected devices through an unauthenticated C++ API. This could occur when the device is accessible over a network.

  • Sensitive data and services at risk.
  • Remote network access can enable exposure.
  • Disruption of operations and data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The presence of an unauthenticated C++ API in SICK TLOC100-100 devices indicates that platform or infrastructure teams are likely responsible for managing this technology, with potential coordination required from network and security teams to assess external exposure. The immediate practical step is to identify all deployed instances of the TLOC100-100, confirm their network accessibility and business criticality, and then engage the accountable owner to plan risk-based remediation.

  • Platform/infrastructure teams own the issue.
  • Verify device network exposure and criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the SICK TLOC100-100 device?

The SICK TLOC100-100 is an industrial hardware component designed for automation and monitoring tasks. It functions within industrial environments to manage data processing or connectivity, often serving as a specialized node in larger operational technology infrastructures.

How does CVE-2025-59461 work?

This vulnerability is classified as CWE-862, which refers to Missing Authorization. It means the device's C++ application programming interface (API) fails to check if a user is authorized before granting access. Because this check is missing, anyone who can reach the API over the network can interact with it as if they were a trusted user.

Do I need to be authenticated to trigger this?

No. The vulnerability exists specifically because the C++ API requires no authentication at all. An attacker does not need to provide a username, password, or token to send commands to the device. Note that the bug is triggered by interacting with the API itself; simply having the device powered on or connected to a local network is not a trigger, but network reachability is required for the attacker to send the necessary requests.

Is my SICK TLOC100-100 at risk if it is internal?

Halo Surface Signal indicates that while industrial devices are often kept on isolated networks, they are sometimes reachable via broader corporate networks or the internet in specific remote monitoring setups. If your device is accessible beyond a strictly secured local segment, it faces a higher probability of being reached by unauthorized network traffic.

What are the first steps to address this?

Start by locating all TLOC100-100 units in your environment. Confirm their current network configuration to understand if they are reachable from outside your protected zones. Once inventoried, coordinate with your infrastructure and security teams to restrict network access to these devices while you await and implement the official security updates provided by the manufacturer.

References