The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-322-05