CVE-2026-0647
Description
An unauthenticated attacker can change the web interface password on Rockwell Automation 1794-AENTR adapters via a crafted HTTP GET request, enabling account takeover and availability loss.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated attacker can change the web interface password on Rockwell Automation 1794-AENTR adapters via a crafted HTTP GET request, enabling account takeover and availability loss.
Vulnerability
An improper authentication vulnerability exists in the embedded web server of Rockwell Automation 1794-AENTR and 1794-AENTRXT FLEX I/O EtherNet/IP adapters running firmware version 2.012. The bug allows an unauthenticated attacker to change the device's web interface password by sending a specially crafted HTTP GET request to a specific endpoint, without requiring prior authentication [1].
Exploitation
No authentication is required to exploit this issue. An attacker with network access to the affected device can craft a malicious HTTP GET request directed at a particular endpoint of the embedded web server. The exact endpoint is not publicly detailed, but the request triggers the password change operation without any session or credential validation [1].
Impact
Successful exploitation grants the attacker the ability to change the web interface password, leading to unauthorized access and account takeover. This can result in loss of the device's embedded web server availability, as legitimate users may be locked out or the web interface compromised for further malicious actions [1].
Mitigation
Rockwell Automation has released firmware version 2.013 which corrects this issue. Users should update all affected devices (catalog numbers 1794-AENTR and 1794-AENTRXT) to firmware 2.013 or later. No workarounds are documented, and this CVE is not listed as a Known Exploited Vulnerability (KEV) as of the advisory publication [1].
AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Rockwell Automation FLEX I/O EtherNet/IP AdaptersCISA ICS Advisories