Home

Description

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

PUBLISHED Reserved 2026-03-05 | Published 2026-03-23 | Updated 2026-03-24 | Assigner CERTVDE




CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-912 Hidden Functionality

Product status

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.3.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.8.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.0.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.0.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.0.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.1.9.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.0.6.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.0.6.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.5.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

Default status
unaffected

0.0.0 (semver) before V1.2.1.S0
affected

References

certvde.com/de/advisories/VDE-2026-020

cve.org (CVE-2026-3587)

nvd.nist.gov (CVE-2026-3587)

Download JSON