CVE-2026-24790
Received
Received - Intake
Remote Authentication Bypass in PLC Allows Unauthorized Control
Publication date: 2026-02-20
Last updated on: 2026-02-20
Assigner: ICS-CERT
Description
Description
The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| welker | welkerscope | * |
| welker | welker_jet | * |
| welker | odoreyes | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |