VYPR
Medium severity5.3NVD Advisory· Published Jun 12, 2026

CVE-2026-11848

CVE-2026-11848

Description

iRM-IEI Remote Management missing authentication allows unauthenticated remote attackers to obtain partial system configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

iRM-IEI Remote Management missing authentication allows unauthenticated remote attackers to obtain partial system configuration.

Vulnerability

A Missing Authentication vulnerability exists in IEI Integration Corp's iRM-IEI Remote Management application. The affected product is iRM-TSi410X before version v1.4.19. An unauthenticated remote attacker can exploit a specific functionality that lacks proper authentication checks, allowing access to partial system configuration information [1][2].

Exploitation

The attacker requires only network access to the management interface; no authentication or user interaction is needed. By sending crafted requests to the vulnerable endpoint, the attacker can retrieve system configuration details without prior authorization [1][2].

Impact

Successful exploitation results in the disclosure of partial system configuration information, compromising confidentiality (low impact). The attacker does not gain write or administrative access, and the scope remains unchanged (CVSS scope: unchanged) [1][2].

Mitigation

IEI Integration Corp released version v1.4.19 of iRM-TSi410X, which addresses this vulnerability. Users should update to v1.4.19 or later. The fix was publicly disclosed on 2026-06-12. No workarounds have been published for unpatched versions [1][2].

AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.