CVE-2026-14837
Received
Received - Intake
Improper Signature Verification in Lenze Products Allows SSH Bypass
Vulnerability report for CVE-2026-14837, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-27
Last updated on: 2026-07-27
Assigner: CERT VDE
Description
Description
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lenze | c430 | to 1.15.2 (exc) |
| lenze | c520 | to 1.15.2 (exc) |
| lenze | c550 | to 1.15.2 (exc) |
| lenze | i950_gena | to 1.14.2 (exc) |
| lenze | i950_genb | to 2.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |