Home
CRITICAL: 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HDefault status
unaffected
Any version before 1.4.0
affected
1.4.0
unaffected
Description
The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials.
Problem types
Product status
Any version before 1.4.0
1.4.0
Credits
Souvik Kandar reported this vulnerability to CISA.
References
www.carlsonsw.com/support-and-training/
www.cve.org/CVERecord?id=CVE-2026-3893
github.com/...p/csaf_files/OT/white/2026/icsa-26-113-02.json