Description
Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers.
Problem types
Product status
Any version before 2.11.0
Any version before 2.12.2026
Credits
Michael Groberman reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-055-03
github.com/...p/csaf_files/OT/white/2026/icsa-26-055-03.json