ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Critical Security Holes Unearthed in Bosch Rexroth’s NXA015S-36V-B Nutrunner

Kyle by Kyle
January 9, 2024
in Exploits
Reading Time: 2 mins read
Critical vulnerabilities found in Bosch Rexroth’s nutrunner risk ransomware attacks; unauthenticated access may compromise safety and production systems.
Share on FacebookShare on Twitter

Nozomi researchers have identified over two dozen vulnerabilities in Bosch Rexroth’s NXA015S-36V-B nutrunner, a crucial pneumatic torque wrench used in safety-critical operations. The flaws, predominantly in the NEXO-OS operating system, could allow unauthenticated attackers to take control, leading to potential ransomware attacks and automation threats across a company’s nutrunners.

Recent investigations by Nozomi researchers have exposed alarming vulnerabilities in Bosch Rexroth’s NXA015S-36V-B product, a cordless, handheld pneumatic torque wrench crucial for safety-critical tightening operations.

Key Findings

  • The NXA015S-36V-B features a built-in display for real-time data and connects wirelessly via an embedded Wi-Fi module, facilitating remote reprogramming.
  • Over two dozen vulnerabilities were uncovered, mainly in the NEXO-OS operating system’s management application, with some affecting communication protocols tied to SCADA, PLC, and other systems.
  • Exploiting these vulnerabilities could grant unauthenticated attackers complete control, potentially leading to ransomware attacks and automation threats across a company’s nutrunners.

Security Implications

Simulated attacks revealed severe consequences, including ransomware rendering devices inoperable and manipulation of tightening program configurations, posing safety risks and financial damage.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Nozomi emphasized the critical role of torque precision in applications like electrical switchboards, where loose connections could lead to fires, and overtightening might result in mechanical failures, warranty claims, and reputational harm.

Vulnerability Details

  • A total of 25 CVE identifiers, with 11 rated as ‘high severity.’
  • Unauthenticated attackers sending network packets can achieve remote code execution with root privileges.
  • Authentication requirements can be bypassed by exploiting chained vulnerabilities, including hardcoded credentials.

Vulnerabilities extend beyond the NXA015S-36V-B model, affecting other Rexroth Nexo nutrunners, including NXA, NXP, and NXV series devices.

Bosch Rexroth has been alerted and plans to patch the flaws by the end of January 2024. The company assures a commitment to security and prompt countermeasures against potential threats.

“Security is a top priority at Bosch Rexroth. Our experts continuously monitor any threats and take immediate countermeasures if necessary…”

“Nozomi Networks informed us some weeks ago that they have found that there is a vulnerability… This patch will be released at the end of January 2024.”

Preventing Exploitation

Nozomi Networks has refrained from disclosing technical information publicly to prevent malicious exploitation of the vulnerabilities.

Previous Post

Global Crackdown on xDedic Dark Web Marketplace Unveils Multinational Criminal Network

Next Post

Capital Health Faces Cyberattack: Lockbit Threatens Data Leak

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.