CVE-2026-33272
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-33272, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: ICS-CERT

Description

A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Red Lion Controls 700 Series 0
Red Lion Controls 700 Series 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a malicious user with physical access to a Red Lion Controls 700 Series switch to reset it to factory settings without authentication. They can then use default admin credentials to gain administrative access and make persistent changes to the configuration file.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized changes to the switch configuration or unexpected factory resets. Inspect the device logs for signs of physical access or configuration modifications. Verify the current configuration against known good backups to identify unauthorized changes.

Impact Analysis

An attacker could gain full administrative control over the switch, alter network configurations, intercept traffic, or disrupt operations. This could lead to unauthorized access, data breaches, or denial of service.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately restrict physical access to the device to prevent unauthorized booting. Change the default administrative credentials to strong, unique passwords. Enable logging and monitor for factory reset events or configuration changes. Update the device firmware if patches are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33272. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart