Zero-DayОригинал на английском
Red Lion Controls N-Tron 700 Series
Русский перевод готовится и скоро появится на сайте. Пока доступен оригинал на английском.
View CSAF Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can cause the switch to r
CISA Alerts··3 мин чтения
View CSAF Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can cause the switch to reboot by navigating to a specific URL on the device. This action can be scripted on the malicious user's local machine to cause continuous rebooting of the switch. The following versions of Red Lion Controls N-Tron 700 Series are affected: 700 Series <=Firmware_3.11.0 (CVE-2026-32645, CVE-2026-39460, CVE-2026-28745, CVE-2026-33367, CVE-2026-29797, CVE-2026-39453, CVE-2026-33272) 700 Series <=Bootloader_2.0.6.1 (CVE-2026-32645, CVE-2026-39460, CVE-2026-28745, CVE-2026-33367, CVE-2026-29797, CVE-2026-39453, CVE-2026-33272) CVSS Vendor Equipment v3 8.3 Red Lion Controls 700 Series 7 Vulnerabilities Use of Hard-coded Credentials, Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Download of Code Without Integrity Check, Reachable Assertion, Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sectors: Commercial Facilities, Communications, Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities Expand All + CVE-2026-32645 Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts. Read More 2 Affected Products Red Lion Controls 700 Series: <=Firmware_3.11.0 Product Status: known_affected Remediations Vendor fix Red Lion controls recommends the following upgrades for the N-Tron 700 Series: Mitigation Upgrade to firmware version 3.11.1 or greater Mitigation Configure or disable the SNMP communities Mitigation Disable access to the web GUI Mitigation The upgrade procedure document can be viewed here.. Mitigation The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here Red Lion Controls 700 Series: <=Bootloader_2.0.6.1 Product Status: known_affected Remediations Vendor fix Red Lion controls recommends the following upgrades for the N-Tron 700 Series: Mitigation Upgrade to firmware version 3.11.1 or greater Mitigation Configure or disable the SNMP communities Mitigation Disable access to the web GUI Mitigation The upgrade procedure document can be viewed here.. Mitigation The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here Additional Metrics Relevant CWE: CWE-798 Use of Hard-coded Credentials CVSS Version Base Score Base Severity Vector String 3.1 6 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N 4.0 9.2 CRITICAL CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N View CVE Details CVE-2026-39460 Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication. Read More 4 Affected Products Red Lion Controls 700 Series: <=Firmware_3.11.0 Product Status: known_affected Remediations Vendor fix Red Lion controls recommends the following upgrades for the N-Tron 700 Series: Mitigation Upgrade to firmware version 3.11.1 or greater Mitigation Configure or disable the SNMP communities Mitigation Disable access to the web GUI Mitigation The upgrade procedure document can be viewed here.. Mitigation The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here Red Lion Controls 700 Series: <=Bootloader_2.0.6.1 Product Status: known_affected Remediations Vendor fix Red Lion controls recommends the following upgrades for the N-Tron 700 Series: Mitigation Upgrade to firmware version 3.11.1 or greater Mi