HIGHCVE-2026-25086Published Modified CNA icscert
CVE-2026-25086: Automated Logic WebCTRL Premium Server Multiple Binds to the Same Port
Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software.
Metrics
- CVSS v3.1
- 7.7
- Severity
- HIGH
- Fixed in
- v8.5
- Affected Products
- 1
Fix available
v8.5
Affected packages
- Automated Logic / WebCTRL Premium Server< v8.5 (from 0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NReferences