Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
All versions
affected
Description
The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical device settings.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
All versions
Credits
Souvik Kandar
References
www.cisa.gov/news-events/ics-advisories/icsa-25-336-02