Description
The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.
Problem types
Product status
Any version
Credits
Abhishek Pandey of Payatu Security Consulting reported this to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-050-03
github.com/...p/csaf_files/OT/white/2026/icsa-26-050-03.json