CVE-2026-29797

Es ist keine Authentifizierung erforderlich, wenn Firmware oder Bootloader aktualisiert werden, was es einfach macht, dass bösartige Date…

high

Description

No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.

Metrics

8.4
Source: cna-v4
Show all metrics
Severity
high
no public PoC known
Published
2026-10-09 14:40 UTC
CWE-494

Weakness classes (CWE)

  • CWE-494Base

    Download of Code Without Integrity Check

    The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-10-09 15:17 UTC· ics-cert@hq.dhs.gov
    • Description: No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
    • CVSS V4.0: AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
    • CWE: CWE-494