Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
v1.600
affected
Description
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Problem types
Product status
v1.600
Credits
Shorabh Karir and Deepak Singh of KPMG reported these vulnerabilities to CISA
References
www.cisa.gov/news-events/ics-advisories/icsa-26-041-02
github.com/...p/csaf_files/OT/white/2026/icsa-26-041-02.json
www.zlmcu.com/en/contact_us.htm