HarborGuard / CVE
Back to search
CRITICALCVE-2026-24789Published Modified CNA icscert

CVE-2026-24789: ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • ZLAN Information Technology Co. / ZLAN5143D
    v1.600
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N