CVE-2026-78319
Received
Received - Intake
Time-of-Check Time-of-Use Race Condition in Product
Vulnerability report for CVE-2026-78319, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-01
Last updated on: 2026-09-01
Assigner: CERT VDE
Description
Description
A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition.
An unauthenticated remote attacker could exploit this race condition to bypass intended security controls.
This may result in the execution of unauthorized code.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sauter | ey_rc504f | to 7.0.0 (exc) |
| sauter | ey_rc505f | to 7.0.0 (exc) |
| sauter | ey6lc12f011 | to 4.0.0 (exc) |
| sauter | ey6as60f011 | to 4.0.0 (exc) |
| sauter | ey6as80f021 | to 4.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-367 | The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. |