Description
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
All versions
Credits
Souvik Kandar of MicroSec reported this vulnerability to CISA
References
www.cisa.gov/news-events/ics-advisories/icsa-26-034-04
github.com/...p/csaf_files/OT/white/2026/icsa-26-034-04.json