CVE-2026-1775
Received
Received - Intake
Unauthenticated Command Injection in Labkotec LID-3300IP Ice Detector
Publication date: 2026-03-03
Last updated on: 2026-03-03
Assigner: ICS-CERT
Description
Description
The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameters and run operational commands when specially crafted packets are sent to the device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| labkotec | lid-3300ip | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |