High severity7.1NVD Advisory· Published Oct 9, 2026
CVE-2026-29797
CVE-2026-29797
Description
No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
1- Red Lion Controls N-Tron 700 SeriesCISA ICS Advisories