Search

Find a vulnerability

Search criteria

    8487 vulnerabilities

    CVE-2026-27873 (GCVE-0-2026-27873)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:27 – Updated: 2026-10-01 21:42
    VLAI
    Summary
    - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
    CWE
    • CWE-798 - - Use of Hard-coded Credentials
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FG Affected: 0 , < 2.0b52 (custom)
        cpe:2.3:a:johnson_controls:easyio_fg:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FG",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "2.0b52",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fg:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.0b52",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.\u003cp\u003eThis issue affects EasyIO FG: before 2.0b52.\u003c/p\u003e"
                }
              ],
              "value": "- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.\n\nThis issue affects EasyIO FG: before 2.0b52."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-70",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-70 - Pasword Spraying"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "CWE-798 - Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:42:09.453Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-27873",
        "datePublished": "2026-10-01T21:27:33.323Z",
        "dateReserved": "2026-02-24T11:29:18.530Z",
        "dateUpdated": "2026-10-01T21:42:09.453Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-64893 (GCVE-0-2026-64893)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:25 – Updated: 2026-10-01 21:25
    VLAI
    Summary
    - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
    CWE
    • CWE-319 - - Cleartext Transmission of Sensitive Information
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO NEO Affected: 0 , < 3.3b25 (custom)
        cpe:2.3:a:johnson_controls:easyio_neo:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO NEO",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.3b25",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_neo:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.3b25",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.\u003cp\u003eThis issue affects EasyIO NEO: before 3.3b25.\u003c/p\u003e"
                }
              ],
              "value": "- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.\n\nThis issue affects EasyIO NEO: before 3.3b25."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-94",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-94 - Man In the Middle Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319 - Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:25:26.090Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-64893",
        "datePublished": "2026-10-01T21:25:26.090Z",
        "dateReserved": "2026-07-20T19:51:19.089Z",
        "dateUpdated": "2026-10-01T21:25:26.090Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-64892 (GCVE-0-2026-64892)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:23 – Updated: 2026-10-01 21:23
    VLAI
    Summary
    - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.
    CWE
    • CWE-200 - - Exposure of Sensitive Information
    Impacted products
    Vendor Product Version
    Johnson Controls Easy IO Neo Affected: 0 , < 3.3b63 (custom)
        cpe:2.3:a:johnson_controls:easy_io_neo:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Easy IO Neo",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.3b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easy_io_neo:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.3b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.\u003cp\u003eThis issue affects Easy IO Neo: before 3.3b63.\u003c/p\u003e"
                }
              ],
              "value": "- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.\n\nThis issue affects Easy IO Neo: before 3.3b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-150",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-150 Collect Data from Common Resource Locations"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200 - Exposure of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:23:33.947Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-64892",
        "datePublished": "2026-10-01T21:23:33.947Z",
        "dateReserved": "2026-07-20T19:51:19.089Z",
        "dateUpdated": "2026-10-01T21:23:33.947Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-34494 (GCVE-0-2026-34494)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:20 – Updated: 2026-10-01 21:20
    VLAI
    Summary
    - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.
    CWE
    Impacted products
    Vendor Product Version
    Johnson Controls Neo Series MVP2 Affected: 0 , < 3.3b63 (custom)
        cpe:2.3:a:johnson_controls:neo_series_mvp2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Neo Series MVP2",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.3b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:neo_series_mvp2:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.3b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.\u003cp\u003eThis issue affects Neo Series MVP2: before 3.3b63.\u003c/p\u003e"
                }
              ],
              "value": "- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.\n\nThis issue affects Neo Series MVP2: before 3.3b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-150",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-150 Collect Data from Common Resource Locations"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1191",
                  "description": "CWE-1191 - On-Chip Debug Interface",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:20:55.416Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-34494",
        "datePublished": "2026-10-01T21:20:55.416Z",
        "dateReserved": "2026-03-30T08:25:11.763Z",
        "dateUpdated": "2026-10-01T21:20:55.416Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-34493 (GCVE-0-2026-34493)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:18 – Updated: 2026-10-01 21:18
    VLAI
    Summary
    - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.
    CWE
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.3b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.3b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.3b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.\u003cp\u003eThis issue affects EasyIO FS32: before 3.3b63.\u003c/p\u003e"
                }
              ],
              "value": "- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.\n\nThis issue affects EasyIO FS32: before 3.3b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-150",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-150 Collect Data from Common Resource Locations"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1191",
                  "description": "CWE-1191 - On-Chip Debug Interface",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:18:55.348Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-34493",
        "datePublished": "2026-10-01T21:18:55.348Z",
        "dateReserved": "2026-03-30T08:25:11.763Z",
        "dateUpdated": "2026-10-01T21:18:55.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71449 (GCVE-0-2026-71449)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:16 – Updated: 2026-10-01 21:44
    VLAI
    Summary
    : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
    CWE
    • CWE-321 - Use of Hard-coded Cryptographic Key
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": ": Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.\u003cp\u003eThis issue affects EasyIO FS32: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": ": Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.\n\nThis issue affects EasyIO FS32: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-37",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-37: Retrieve Embedded Sensitive Data"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-321",
                  "description": "CWE-321: Use of Hard-coded Cryptographic Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:44:04.397Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-71449",
        "datePublished": "2026-10-01T21:16:57.610Z",
        "dateReserved": "2026-08-06T19:11:09.315Z",
        "dateUpdated": "2026-10-01T21:44:04.397Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71448 (GCVE-0-2026-71448)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:15 – Updated: 2026-10-01 21:41
    VLAI
    Summary
    : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.
    CWE
    • CWE-1188 - Insecure Default Initialization of Resource
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": ": Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.\u003cp\u003eThis issue affects EasyIO FS32: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": ": Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.\n\nThis issue affects EasyIO FS32: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115: Authentication Abuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1188",
                  "description": "CWE-1188: Insecure Default Initialization of Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:41:21.737Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-71448",
        "datePublished": "2026-10-01T21:15:22.406Z",
        "dateReserved": "2026-08-06T19:11:09.314Z",
        "dateUpdated": "2026-10-01T21:41:21.737Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71454 (GCVE-0-2026-71454)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:13 – Updated: 2026-10-01 21:41
    VLAI
    Summary
    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    Impacted products
    Vendor Product Version
    CWE-79 - Cross-site Scripting CAPEC-63 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:cwe-79_-_cross-site_scripting:capec-63:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CAPEC-63",
              "vendor": "CWE-79 - Cross-site Scripting",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:cwe-79_-_cross-site_scripting:capec-63:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027) vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).\u003cp\u003eThis issue affects CAPEC-63: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": "Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027) vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).\n\nThis issue affects CAPEC-63: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-63",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-63 Cross-Site Scripting (XSS)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:41:02.568Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-71454",
        "datePublished": "2026-10-01T21:13:17.159Z",
        "dateReserved": "2026-08-06T19:11:09.315Z",
        "dateUpdated": "2026-10-01T21:41:02.568Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71453 (GCVE-0-2026-71453)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:10 – Updated: 2026-10-01 21:40
    VLAI
    Summary
    - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
    CWE
    • CWE-73 - - External Control of File Name or Path
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.\u003cp\u003eThis issue affects EasyIO FS32: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": "- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.\n\nThis issue affects EasyIO FS32: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 - traversal attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 - External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:40:06.795Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-71453",
        "datePublished": "2026-10-01T21:10:08.583Z",
        "dateReserved": "2026-08-06T19:11:09.315Z",
        "dateUpdated": "2026-10-01T21:40:06.795Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71452 (GCVE-0-2026-71452)

    Vulnerability from cvelistv5 – Published: 2026-10-01 21:06 – Updated: 2026-10-01 21:43
    VLAI
    Summary
    - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
    CWE
    • CWE-78 - - OS Command Injection
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.\u003cp\u003eThis issue affects EasyIO FS32: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": "- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.\n\nThis issue affects EasyIO FS32: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 - OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:43:25.153Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-71452",
        "datePublished": "2026-10-01T21:06:20.659Z",
        "dateReserved": "2026-08-06T19:11:09.315Z",
        "dateUpdated": "2026-10-01T21:43:25.153Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71451 (GCVE-0-2026-71451)

    Vulnerability from cvelistv5 – Published: 2026-10-01 20:59 – Updated: 2026-10-01 21:43
    VLAI
    Summary
    - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.
    CWE
    • CWE-78 - - OS Command Injection
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection.\u003cp\u003eThis issue affects EasyIO FS32: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": "- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection.\n\nThis issue affects EasyIO FS32: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-248",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-248 - Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 - OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:43:04.834Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-71451",
        "datePublished": "2026-10-01T20:59:35.064Z",
        "dateReserved": "2026-08-06T19:11:09.315Z",
        "dateUpdated": "2026-10-01T21:43:04.834Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27874 (GCVE-0-2026-27874)

    Vulnerability from cvelistv5 – Published: 2026-10-01 20:55 – Updated: 2026-10-01 21:42
    VLAI
    Summary
    : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
    CWE
    • CWE-798 - Use of Hard-coded Credentials
    Impacted products
    Vendor Product Version
    Johnson Controls EasyIO FS32 Affected: 0 , < 3.0b63 (custom)
        cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "EasyIO FS32",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "3.0b63",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easyio_fs32:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.0b63",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": ": Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials.\u003cp\u003eThis issue affects EasyIO FS32: before 3.0b63.\u003c/p\u003e"
                }
              ],
              "value": ": Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials.\n\nThis issue affects EasyIO FS32: before 3.0b63."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-112",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-112: Exploitation of Default or Hard-coded Credentials"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "CWE-798: Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:42:44.495Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-27874",
        "datePublished": "2026-10-01T20:55:59.314Z",
        "dateReserved": "2026-02-24T11:29:18.530Z",
        "dateUpdated": "2026-10-01T21:42:44.495Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27872 (GCVE-0-2026-27872)

    Vulnerability from cvelistv5 – Published: 2026-10-01 18:57 – Updated: 2026-10-01 21:38
    VLAI
    Title
    EasyIO FG
    Summary
    - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 19:10 UTC
    CWE
    • CWE-269 - - Improper Privilege Management
    Impacted products
    Vendor Product Version
    Johnson Controls Easy IO FG Affected: 0 , < 2.0b52 (custom)
        cpe:2.3:a:johnson_controls:easy_io_fg:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27872",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T19:10:39.428388Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T19:10:49.540Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Easy IO FG",
              "vendor": "Johnson Controls",
              "versions": [
                {
                  "lessThan": "2.0b52",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:johnson_controls:easy_io_fg:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.0b52",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Gardois, Zachary Bushell and Lorenzo De Carli"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force).\u003cp\u003eThis issue affects Easy IO FG: before 2.0b52.\u003c/p\u003e"
                }
              ],
              "value": "- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force).\n\nThis issue affects Easy IO FG: before 2.0b52."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-30",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-30 (Brute Force)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 - Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T21:38:28.271Z",
            "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
            "shortName": "jci"
          },
          "references": [
            {
              "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "EasyIO FG",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "assignerShortName": "jci",
        "cveId": "CVE-2026-27872",
        "datePublished": "2026-10-01T18:57:16.163Z",
        "dateReserved": "2026-02-24T11:29:18.530Z",
        "dateUpdated": "2026-10-01T21:38:28.271Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104018 (GCVE-0-2026-104018)

    Vulnerability from cvelistv5 – Published: 2026-10-01 17:35 – Updated: 2026-10-02 03:55
    VLAI
    Title
    VxWorks 7 improper privilege management
    Summary
    An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authorized to run. Successful exploitation can result in privilege escalation, with impact to the confidentiality, integrity, and availability of the affected device. The issue affects all versions of VxWorks 7 prior to 26.09.  It has been fixed in 26.09.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 00:00 UTC
    CWE
    • cwe-269 improper Privilege Management
    • CWE-269 - Improper Privilege Management
    Impacted products
    Date Public
    2026-10-01 17:14
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104018",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-269",
                    "description": "CWE-269 Improper Privilege Management",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T03:55:35.132Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "VxWorks 7",
              "vendor": "Wind River Systems Inc",
              "versions": [
                {
                  "status": "affected",
                  "version": "VxWorks 7"
                }
              ]
            }
          ],
          "datePublic": "2026-10-01T17:14:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7\u0026nbsp;when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authorized to run. Successful exploitation can result in privilege escalation, with impact to the confidentiality, integrity, and availability of the affected device.\u0026nbsp;\u003cspan\u003eThe issue affects all versions of VxWorks 7 prior to 26.09.\u0026nbsp; It has been fixed in 26.09.\u003c/span\u003e"
                }
              ],
              "value": "An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7\u00a0when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute commands they are not authorized to run. Successful exploitation can result in privilege escalation, with impact to the confidentiality, integrity, and availability of the affected device.\u00a0The issue affects all versions of VxWorks 7 prior to 26.09.\u00a0 It has been fixed in 26.09."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "cwe-269 improper Privilege Management",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T18:07:25.396Z",
            "orgId": "0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8",
            "shortName": "WindRiver"
          },
          "references": [
            {
              "url": "https://support2.windriver.com/index.php?page=cve\u0026on=view\u0026id=CVE-2026-104018"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "VxWorks 7 improper privilege management",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8",
        "assignerShortName": "WindRiver",
        "cveId": "CVE-2026-104018",
        "datePublished": "2026-10-01T17:35:20.063Z",
        "dateReserved": "2026-10-01T16:57:29.934Z",
        "dateUpdated": "2026-10-02T03:55:35.132Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-41753 (GCVE-0-2025-41753)

    Vulnerability from cvelistv5 – Published: 2026-10-01 06:42 – Updated: 2026-10-01 19:11
    VLAI
    Title
    Path traversal in dynamically created BACnet File Objects
    Summary
    The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 19:11 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    WAGO 0751-9x01 Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0750-811x-xxxx-xxxx Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0750-821x-xxx-xxx Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-420x-8000-000x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-430x-8000-000x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-520x-8000-000x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-530x-8000-000x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-620x-8000-000x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-630x-8000-000x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0752-8303-8000-0002 Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0762-340x Affected: 1.0.0 , < 4.8.9 (semver)
    Create a notification for this product.
    WAGO 0751-9x01 Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0750-811x-xxxx-xxxx Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0750-821x-xxx-xxx Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-420x-8000-000x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-430x-8000-000x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-520x-8000-000x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-530x-8000-000x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-620x-8000-000x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-630x-8000-000x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0752-8303-8000-0002 Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    WAGO 0762-340x Affected: 1.0.0 , < 4.8.9 (70) (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-41753",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T19:11:00.419667Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T19:11:15.337Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "0751-9x01",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0750-811x-xxxx-xxxx",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0750-821x-xxx-xxx",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-420x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-430x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-520x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-530x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-620x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-630x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0752-8303-8000-0002",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-340x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0751-9x01",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0750-811x-xxxx-xxxx",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0750-821x-xxx-xxx",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-420x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-430x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-520x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-530x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-620x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-630x-8000-000x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0752-8303-8000-0002",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "0762-340x",
              "vendor": "WAGO",
              "versions": [
                {
                  "lessThan": "4.8.9 (70)",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.\u003c/p\u003e"
                }
              ],
              "value": "The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T06:42:00.734Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2025-102/"
            }
          ],
          "source": {
            "advisory": "VDE-2025-102",
            "defect": [
              "CERT@VDE#641894"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Path traversal in dynamically created BACnet File Objects",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2025-41753",
        "datePublished": "2026-10-01T06:42:00.734Z",
        "dateReserved": "2025-04-16T11:18:45.759Z",
        "dateUpdated": "2026-10-01T19:11:15.337Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13313 (GCVE-0-2026-13313)

    Vulnerability from cvelistv5 – Published: 2026-10-01 02:00 – Updated: 2026-10-02 03:55
    VLAI
    Summary
    An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 00:00 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    ASUS Router Affected: 3.0.0.4_386 series (custom)
    Affected: 3.0.0.4_388 series (custom)
    Affected: 3.0.0.6_102 series (custom)
        cpe:2.3:a:asus:router:3.0.0.4_386_series:*:*:*:*:*:*:*
        cpe:2.3:a:asus:router:3.0.0.4_388_series:*:*:*:*:*:*:*
        cpe:2.3:a:asus:router:3.0.0.6_102_series:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-13313",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T03:55:30.187Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Router",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.0.0.4_386 series",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "3.0.0.4_388 series",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "3.0.0.6_102 series",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:router:3.0.0.4_386_series:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:asus:router:3.0.0.4_388_series:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:asus:router:3.0.0.6_102_series:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router.\u003cbr\u003eRefer to the \u0027 Security Update for ASUS Router Firmware\u0026nbsp;\u0027 section on the ASUS Security Advisory for more information."
                }
              ],
              "value": "An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router.\nRefer to the \u0027 Security Update for ASUS Router Firmware\u00a0\u0027 section on the ASUS Security Advisory for more information."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.9,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-489",
                  "description": "CWE-489: Active Debug Code",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T02:00:57.434Z",
            "orgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
            "shortName": "ASUS"
          },
          "references": [
            {
              "url": "https://www.asus.com/security-advisory"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
        "assignerShortName": "ASUS",
        "cveId": "CVE-2026-13313",
        "datePublished": "2026-10-01T02:00:57.434Z",
        "dateReserved": "2026-06-25T06:14:34.338Z",
        "dateUpdated": "2026-10-02T03:55:30.187Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-14157 (GCVE-0-2026-14157)

    Vulnerability from cvelistv5 – Published: 2026-10-01 02:00 – Updated: 2026-10-02 03:55
    VLAI
    Summary
    Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 00:00 UTC
    CWE
    • CWE-134 - Use of Externally-Controlled Format String
    References
    Impacted products
    Vendor Product Version
    ASUS Router Affected: 3.0.0.6_102 series (custom)
        cpe:2.3:a:asus:router:3.0.0.6_102_series:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14157",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T03:55:30.930Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Router",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.0.0.6_102 series",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:router:3.0.0.6_102_series:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-134",
                  "description": "CWE-134: Use of Externally-Controlled Format String",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T02:00:34.461Z",
            "orgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
            "shortName": "ASUS"
          },
          "references": [
            {
              "url": "https://www.asus.com/security-advisory"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
        "assignerShortName": "ASUS",
        "cveId": "CVE-2026-14157",
        "datePublished": "2026-10-01T02:00:34.461Z",
        "dateReserved": "2026-06-30T00:27:11.829Z",
        "dateUpdated": "2026-10-02T03:55:30.930Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93495 (GCVE-0-2026-93495)

    Vulnerability from cvelistv5 – Published: 2026-10-01 02:00 – Updated: 2026-10-01 15:56
    VLAI
    Summary
    Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:56 UTC
    CWE
    • CWE-665 - Improper Initialization
    References
    Impacted products
    Vendor Product Version
    ASUS Motherboard(PRIME Z390-A ) Affected: through 2101 (custom)
        cpe:2.3:a:asus:motherboard_prime_z390-a_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(PRIME Z390-A/H10 ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_prime_z390-a_h10_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI HERO ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_hero_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI HERO (WI-FI) ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_hero_wi-fi_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI FORMULA ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_formula_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI CODE ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_code_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI EXTREME ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_extreme_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI APEX ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_apex_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG MAXIMUS XI GENE ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_maximus_xi_gene_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG STRIX Z390-E GAMING ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_strix_z390-e_gaming_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(ROG STRIX Z390-F GAMING ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_rog_strix_z390-f_gaming_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(Pro WS C246-ACE ) Affected: through 2101
        cpe:2.3:a:asus:motherboard_pro_ws_c246-ace_:through_2101:*:*:*:*:*:*:*
    Create a notification for this product.
    ASUS Motherboard(WS Z390 PRO ) Affected: through 1401
        cpe:2.3:a:asus:motherboard_ws_z390_pro_:through_1401:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93495",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:56:01.357635Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:56:20.775Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(PRIME Z390-A )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(PRIME Z390-A/H10 )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI HERO )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI HERO (WI-FI) )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI FORMULA )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI CODE )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI EXTREME )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI APEX )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG MAXIMUS XI GENE )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG STRIX Z390-E GAMING )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(ROG STRIX Z390-F GAMING )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(Pro WS C246-ACE )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2101"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Motherboard(WS Z390 PRO )",
              "vendor": "ASUS",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 1401"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_prime_z390-a_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_prime_z390-a_h10_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_hero_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_hero_wi-fi_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_formula_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_code_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_extreme_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_apex_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_maximus_xi_gene_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_strix_z390-e_gaming_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_rog_strix_z390-f_gaming_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_pro_ws_c246-ace_:through_2101:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                },
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:asus:motherboard_ws_z390_pro_:through_1401:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "PHYSICAL",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-665",
                  "description": "CWE-665\uff1aImproper Initialization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T02:00:12.144Z",
            "orgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
            "shortName": "ASUS"
          },
          "references": [
            {
              "url": "https://www.asus.com/security-advisory"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
        "assignerShortName": "ASUS",
        "cveId": "CVE-2026-93495",
        "datePublished": "2026-10-01T02:00:12.144Z",
        "dateReserved": "2026-09-18T07:27:07.993Z",
        "dateUpdated": "2026-10-01T15:56:20.775Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75969 (GCVE-0-2026-75969)

    Vulnerability from cvelistv5 – Published: 2026-09-30 16:27 – Updated: 2026-09-30 20:01
    VLAI
    Title
    PTZOptics Missing Authentication in Firmware Upload
    Summary
    Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials. This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects: * Move 4K 12X before: 0.0.98 * Move 4K 20X before: 0.1.33 * Move 4K 30X before: 2.1.17 * Link 4K 12X before: 0.0.99 * Link 4K 20X before: 0.1.37 * Link 4K 30X before: 2.1.18 * Move SE 12X before: 9.1.66 * Move SE 20X before: 9.1.44 * Move SE 30X before: 9.1.46 * Studio 4K 12X before: 8.3.32 * Studio 4K 20X before: 8.3.32 * Studio SE 12X before: 8.3.32 * Studio SE 20X before: 8.3.32 * All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions * Upgrade Tool - All versions
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 18:30 UTC
    CWE
    • CWE-306 - Missing authentication for critical function
    References
    Impacted products
    Vendor Product Version
    PTZOptics Move 4K 12X Affected: 0 , < 0.0.98 (custom)
    Create a notification for this product.
    PTZOptics Move 4K 20X Affected: 0 , < 0.1.33 (custom)
    Create a notification for this product.
    PTZOptics Move 4K 30X Affected: 0 , < 2.1.17 (custom)
    Create a notification for this product.
    PTZOptics Link 4K 12X Affected: 0 , < 0.0.99 (custom)
    Create a notification for this product.
    PTZOptics Link 4K 20X Affected: 0 , < 0.1.37 (custom)
    Create a notification for this product.
    PTZOptics Link 4K 30X Affected: 0 , < 2.1.18 (custom)
    Create a notification for this product.
    PTZOptics Move SE 12X Affected: 0 , < 9.1.66 (custom)
    Create a notification for this product.
    PTZOptics Move SE 20X Affected: 0 , < 9.1.44 (custom)
    Create a notification for this product.
    PTZOptics Move SE 30X Affected: 0 , < 9.1.46 (custom)
    Create a notification for this product.
    PTZOptics Studio 4K 12X Affected: 0 , < 8.3.32 (custom)
    Create a notification for this product.
    PTZOptics Studio 4K 20X Affected: 0 , < 8.3.32 (custom)
    Create a notification for this product.
    PTZOptics Studio SE 12X Affected: 0 , < 8.3.32 (custom)
    Create a notification for this product.
    PTZOptics Studio SE 20X Affected: 0 , < 8.3.32 (custom)
    Create a notification for this product.
    PTZOptics PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2 Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PT12X-USB-GY-G2, PT12X-USB-WH-G2 Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2 Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PT20X-USB-GY-G2, PT20X-USB-WH-G2 Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2 Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PTVL-ZCAM, PTVL-NDI-ZCAM Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2 Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PT12X-ZCAM, PT12X-NDI-ZCAM Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics PT20X-ZCAM, PT20X-NDI-ZCAM Affected: 0 (custom)
    Create a notification for this product.
    PTZOptics Studio Pro Affected: 0
    Create a notification for this product.
    PTZOptics Upgrade Tool Affected: 0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75969",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T18:30:11.739848Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T20:01:02.432Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Move 4K 12X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "0.0.98",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Move 4K 20X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "0.1.33",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Move 4K 30X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "2.1.17",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Link 4K 12X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "0.0.99",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Link 4K 20X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "0.1.37",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Link 4K 30X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "2.1.18",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Move SE 12X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "9.1.66",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Move SE 20X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "9.1.44",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Move SE 30X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "9.1.46",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Studio 4K 12X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "8.3.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Studio 4K 20X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "8.3.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Studio SE 12X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "8.3.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Studio SE 20X",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "lessThan": "8.3.32",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT12X-USB-GY-G2, PT12X-USB-WH-G2",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT20X-USB-GY-G2, PT20X-USB-WH-G2",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PTVL-ZCAM, PTVL-NDI-ZCAM",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT12X-ZCAM, PT12X-NDI-ZCAM",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "PT20X-ZCAM, PT20X-NDI-ZCAM",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Studio Pro",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "Firmware Update"
              ],
              "product": "Upgrade Tool",
              "vendor": "PTZOptics",
              "versions": [
                {
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Haverford Systems Inc. \u0026 PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eMissing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\u003cbr\u003e\n\u003cbr\u003eThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eMove 4K 12X before: 0.0.98\u003c/li\u003e\u003cli\u003eMove 4K 20X before: 0.1.33\u003c/li\u003e\u003cli\u003eMove 4K 30X before: 2.1.17\u003c/li\u003e\u003cli\u003eLink 4K 12X before: 0.0.99\u003c/li\u003e\u003cli\u003eLink 4K 20X before: 0.1.37\u003c/li\u003e\u003cli\u003eLink 4K 30X before: 2.1.18\u003c/li\u003e\u003cli\u003eMove SE 12X before: 9.1.66\u003c/li\u003e\u003cli\u003eMove SE 20X before: 9.1.44\u003c/li\u003e\u003cli\u003eMove SE 30X before: 9.1.46\u003c/li\u003e\u003cli\u003eStudio 4K 12X before: 8.3.32\u003c/li\u003e\u003cli\u003eStudio 4K 20X before: 8.3.32\u003c/li\u003e\u003cli\u003eStudio SE 12X before: 8.3.32\u003c/li\u003e\u003cli\u003eStudio SE 20X before: 8.3.32\u003c/li\u003e\u003cli\u003eAll Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\u003c/li\u003e\u003cli\u003eUpgrade Tool - All versions\u0026nbsp;\u003cbr\u003e\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\n\n\nThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\n\n\n\n\n\n  *  Move 4K 12X before: 0.0.98\n  *  Move 4K 20X before: 0.1.33\n  *  Move 4K 30X before: 2.1.17\n  *  Link 4K 12X before: 0.0.99\n  *  Link 4K 20X before: 0.1.37\n  *  Link 4K 30X before: 2.1.18\n  *  Move SE 12X before: 9.1.66\n  *  Move SE 20X before: 9.1.44\n  *  Move SE 30X before: 9.1.46\n  *  Studio 4K 12X before: 8.3.32\n  *  Studio 4K 20X before: 8.3.32\n  *  Studio SE 12X before: 8.3.32\n  *  Studio SE 20X before: 8.3.32\n  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\n  *  Upgrade Tool - All versions"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-638",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-638 Altered Component Firmware"
                }
              ]
            },
            {
              "capecId": "CAPEC-669",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-669 Alteration of a Software Update"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "USER",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "UNREPORTED",
                "privilegesRequired": "NONE",
                "providerUrgency": "RED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "CONCENTRATED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R:U/V:C/RE:L/U:Red",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "LOW"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:27:51.490Z",
            "orgId": "16cac6a8-cc1e-4741-89aa-6b97e2437706",
            "shortName": "hsi"
          },
          "references": [
            {
              "url": "https://psirt.havsys.com/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003e\u003cb\u003eProduct\u003c/b\u003e\u003c/td\u003e\u003ctd\u003e\u003cb\u003eRemediation\u003c/b\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eMove 4K 12X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 0.0.98.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eMove 4K 20X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 0.1.33.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eMove 4K 30X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 2.1.17.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eLink 4K 12X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 0.0.99.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eLink 4K 20X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 0.1.37.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eLink 4K 30X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 2.1.18.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eMove SE 12X\u0026nbsp;\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 9.1.66.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eMove SE 20X\u0026nbsp;\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 9.1.44.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eMove SE 30X\u0026nbsp;\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 9.1.46.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eStudio 4K 12X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 8.3.32\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eStudio 4K 20X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 8.3.32.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eStudio SE 12X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 8.3.32.\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003eStudio SE 20X\u003c/td\u003e\u003ctd\u003eUpdate to Firmware 8.3.32\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "ProductRemediationMove 4K 12XUpdate to Firmware 0.0.98.Move 4K 20XUpdate to Firmware 0.1.33.Move 4K 30XUpdate to Firmware 2.1.17.Link 4K 12XUpdate to Firmware 0.0.99.Link 4K 20XUpdate to Firmware 0.1.37.Link 4K 30XUpdate to Firmware 2.1.18.Move SE 12X\u00a0Update to Firmware 9.1.66.Move SE 20X\u00a0Update to Firmware 9.1.44.Move SE 30X\u00a0Update to Firmware 9.1.46.Studio 4K 12XUpdate to Firmware 8.3.32Studio 4K 20XUpdate to Firmware 8.3.32.Studio SE 12XUpdate to Firmware 8.3.32.Studio SE 20XUpdate to Firmware 8.3.32"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PTZOptics Missing Authentication in Firmware Upload",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cul\u003e\u003cli\u003eDisable network services until the firmware can be updated.\u003c/li\u003e\u003cli\u003eRestrict access to the camera to a trusted management VLAN.\u003c/li\u003e\u003c/ul\u003e"
                }
              ],
              "value": "*  Disable network services until the firmware can be updated.\n  *  Restrict access to the camera to a trusted management VLAN."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "16cac6a8-cc1e-4741-89aa-6b97e2437706",
        "assignerShortName": "hsi",
        "cveId": "CVE-2026-75969",
        "datePublished": "2026-09-30T16:27:51.490Z",
        "dateReserved": "2026-08-18T17:26:08.229Z",
        "dateUpdated": "2026-09-30T20:01:02.432Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76992 (GCVE-0-2026-76992)

    Vulnerability from cvelistv5 – Published: 2026-09-30 11:07 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Uncontrolled Memory Allocation in CODESYS Gateway Client
    Summary
    The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 14:48 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    CODESYS Development System 3 Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Gateway Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Edge Gateway for Windows Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS HMI (SL) Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS OPC DA Server SL Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS PLCHandler Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Runtime Toolkit Affected: 3.0.0.0 , < 3.5.22.40 (generic)
    Create a notification for this product.
    CODESYS Edge Gateway for Linux Affected: 3.15.0.0 , < 4.23.0.0 (generic)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76992",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T14:48:15.816736Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:07.834Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Development System 3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Gateway",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Edge Gateway for Windows",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "OPC DA Server SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "PLCHandler",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Runtime Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "generic"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Edge Gateway for Linux",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.15.0.0",
                  "versionType": "generic"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_development_system_3:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_gateway:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_edge_gateway_for_windows:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_opc_da_server_sl:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_plchandler:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "3.5.22.40",
                      "versionStartIncluding": "3.0.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:codesys:codesys_edge_gateway_for_linux:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.23.0.0",
                      "versionStartIncluding": "3.15.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Delta Electronics Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.\u003c/p\u003e"
                }
              ],
              "value": "The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T11:07:45.751Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-094/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-094",
            "defect": [
              "CERT@VDE#642222"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Uncontrolled Memory Allocation in CODESYS Gateway Client",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-76992",
        "datePublished": "2026-09-30T11:07:45.751Z",
        "dateReserved": "2026-08-20T06:57:08.465Z",
        "dateUpdated": "2026-09-30T15:28:07.834Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79625 (GCVE-0-2026-79625)

    Vulnerability from cvelistv5 – Published: 2026-09-30 09:23 – Updated: 2026-09-30 13:49
    VLAI
    Title
    Improper Synchronization in Monitoring in CODESYS Control Runtime
    Summary
    Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 13:49 UTC
    CWE
    • CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
    References
    Impacted products
    Vendor Product Version
    CODESYS Control RTE (SL) Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS Control RTE (for Beckhoff CX) SL Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS Control Win (SL) Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS Runtime Toolkit Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS Safety SIL2 Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS HMI (SL) Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS Development System 3 Affected: 3.0.0.0 , < 3.5.22.40 (semver)
    Create a notification for this product.
    CODESYS Control for BeagleBone SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for emPC-A/iMX6 SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for IOT2000 SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for Linux ARM SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for Linux SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for PFC100 SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for PFC200 SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for PLCnext SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for Raspberry Pi SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Control for WAGO Touch Panels 600 SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    CODESYS Virtual Control SL Affected: 3.5.0.0 , < 4.23.0.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79625",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T13:49:04.420443Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T13:49:14.992Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Control RTE (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control RTE (for Beckhoff CX) SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control Win (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Runtime Toolkit",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Safety SIL2",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "HMI (SL)",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Development System 3",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "3.5.22.40",
                  "status": "affected",
                  "version": "3.0.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for BeagleBone SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for emPC-A/iMX6 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for IOT2000 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for Linux ARM SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for Linux SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for PFC100 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for PFC200 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for PLCnext SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for Raspberry Pi SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Control for WAGO Touch Panels 600 SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Virtual Control SL",
              "vendor": "CODESYS",
              "versions": [
                {
                  "lessThan": "4.23.0.0",
                  "status": "affected",
                  "version": "3.5.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAffected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.\u003c/p\u003e"
                }
              ],
              "value": "Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-362",
                  "description": "CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T09:23:16.775Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-097/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-097",
            "defect": [
              "CERT@VDE#642221"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Improper Synchronization in Monitoring in CODESYS Control Runtime",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-79625",
        "datePublished": "2026-09-30T09:23:16.775Z",
        "dateReserved": "2026-08-25T08:46:38.207Z",
        "dateUpdated": "2026-09-30T13:49:14.992Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71189 (GCVE-0-2026-71189)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:46 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT Cross-site Scripting
    Summary
    An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 14:59 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71189",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T14:59:47.914220Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:14.261Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user\u0027s browser in the context of that user\u0027s session with the application."
                }
              ],
              "value": "An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user\u0027s browser in the context of that user\u0027s session with the application."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:46:48.138Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT Cross-site Scripting",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-71189",
        "datePublished": "2026-09-29T21:46:48.138Z",
        "dateReserved": "2026-08-10T17:31:09.953Z",
        "dateUpdated": "2026-09-30T15:28:14.261Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-69662 (GCVE-0-2026-69662)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:44 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT Eval Injection
    Summary
    The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-69662",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:00:00.522671Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:14.420Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The application uses unsafe functions that allow execution of inline scripts and string evaluation functions."
                }
              ],
              "value": "The application uses unsafe functions that allow execution of inline scripts and string evaluation functions."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 2.1,
                "baseSeverity": "LOW",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-95",
                  "description": "CWE-95",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:44:07.903Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT Eval Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-69662",
        "datePublished": "2026-09-29T21:44:07.903Z",
        "dateReserved": "2026-08-10T17:31:09.958Z",
        "dateUpdated": "2026-09-30T15:28:14.420Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71302 (GCVE-0-2026-71302)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:41 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT Session Fixation
    Summary
    The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71302",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:00:36.553531Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:14.550Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover."
                }
              ],
              "value": "The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-384",
                  "description": "CWE-384",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:41:11.253Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT Session Fixation",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-71302",
        "datePublished": "2026-09-29T21:41:11.253Z",
        "dateReserved": "2026-08-10T17:31:09.961Z",
        "dateUpdated": "2026-09-30T15:28:14.550Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-72507 (GCVE-0-2026-72507)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:36 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT SQL Injection
    Summary
    The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:01 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-72507",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:01:04.789981Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:14.706Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"reportType\" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability."
                }
              ],
              "value": "The \"reportType\" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:36:53.928Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-72507",
        "datePublished": "2026-09-29T21:36:53.928Z",
        "dateReserved": "2026-08-10T17:31:09.965Z",
        "dateUpdated": "2026-09-30T15:28:14.706Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68068 (GCVE-0-2026-68068)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:33 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT SQL Injection
    Summary
    The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:19 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68068",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:19:39.216510Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:14.845Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"screenID\" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability."
                }
              ],
              "value": "The \"screenID\" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:33:47.332Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-68068",
        "datePublished": "2026-09-29T21:33:47.332Z",
        "dateReserved": "2026-08-10T17:31:09.969Z",
        "dateUpdated": "2026-09-30T15:28:14.845Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-68954 (GCVE-0-2026-68954)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:32 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT SQL Injection
    Summary
    The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:19 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-68954",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:19:46.724891Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:14.972Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"pattern\" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability."
                }
              ],
              "value": "The \"pattern\" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:32:05.984Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-68954",
        "datePublished": "2026-09-29T21:32:05.984Z",
        "dateReserved": "2026-08-10T17:31:09.972Z",
        "dateUpdated": "2026-09-30T15:28:14.972Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63713 (GCVE-0-2026-63713)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:30 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT SQL Injection
    Summary
    The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:19 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63713",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:19:54.167215Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:15.150Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"search\" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability."
                }
              ],
              "value": "The \"search\" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:30:32.531Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-63713",
        "datePublished": "2026-09-29T21:30:32.531Z",
        "dateReserved": "2026-08-10T17:31:09.976Z",
        "dateUpdated": "2026-09-30T15:28:15.150Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-72510 (GCVE-0-2026-72510)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:28 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT SQL Injection
    Summary
    The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:20 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-72510",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:20:08.630311Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:15.314Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"supplier_no\" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection."
                }
              ],
              "value": "The \"supplier_no\" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:28:26.762Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT SQL Injection",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-72510",
        "datePublished": "2026-09-29T21:28:26.762Z",
        "dateReserved": "2026-08-10T17:31:09.979Z",
        "dateUpdated": "2026-09-30T15:28:15.314Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-70356 (GCVE-0-2026-70356)

    Vulnerability from cvelistv5 – Published: 2026-09-29 21:26 – Updated: 2026-09-30 15:28
    VLAI
    Title
    Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type
    Summary
    The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 15:03 UTC
    CWE
    Impacted products
    Vendor Product Version
    Toptech Systems TMS7 Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Toptech Systems TopHAT Affected: 7.6.3
    Unaffected: 7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-70356",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T15:03:03.889713Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T15:28:15.470Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "TMS7",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TopHAT",
              "vendor": "Toptech Systems",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "unaffected",
                  "version": "7.8"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server."
                }
              ],
              "value": "The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T21:26:22.603Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "url": "https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            },
            {
              "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02"
            },
            {
              "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\u003cbr\u003e\u003ca href=\"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security\"\u003ehttps://www.toptech.com/blog/tms7-version-7-8-strengthens-security\u003c/a\u003e"
                }
              ],
              "value": "Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog.\n https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"
            }
          ],
          "source": {
            "advisory": "ICSA-26-272-02",
            "discovery": "EXTERNAL"
          },
          "title": "Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2026-70356",
        "datePublished": "2026-09-29T21:26:22.603Z",
        "dateReserved": "2026-08-10T17:31:09.982Z",
        "dateUpdated": "2026-09-30T15:28:15.470Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }