CVE-2026-5416
Description
A command injection flaw in the name parameter of TURCK TBEN-Lx-SE-M2 Managed Ethernet Switches allows low-privileged remote attackers to execute arbitrary commands and fully compromise the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A command injection flaw in the name parameter of TURCK TBEN-Lx-SE-M2 Managed Ethernet Switches allows low-privileged remote attackers to execute arbitrary commands and fully compromise the device.
Vulnerability
A command injection vulnerability exists in the Managed Ethernet Switch series TBEN-Lx-SE-M2 (models including TBEN-L4-SE-M2) running firmware versions prior to 2.1.2.0. The issue originates from improper neutralization of special elements used in a name parameter [1]. An attacker with low privileges can send specially crafted input to the vulnerable parameter, which is then processed by the device's command execution path, leading to arbitrary command injection.
Exploitation
An attacker requires low-privileged network access to the managed Ethernet switch. No authentication is necessary beyond the low-privilege level already assumed, and the vulnerability can be triggered remotely without user interaction. By injecting operating system commands into the name parameter (e.g., via a crafted HTTP request or other management interface), the attacker can execute arbitrary commands in the context of the device's firmware [1].
Impact
Successful exploitation results in full compromise of the switch's system. The attacker gains the ability to execute arbitrary commands at a high privilege level, leading to complete loss of confidentiality, integrity, and availability of the device. This can allow unauthorized access to network traffic, modification of device configuration, denial of service, or further lateral movement within the network [1].
Mitigation
TURCK has addressed this vulnerability in firmware version 2.1.2.0, released on 19 May 2026 [1]. Users should upgrade all affected TBEN-Lx-SE-M2 devices to firmware version 2.1.2.0 or later immediately. Discontinuing use of end-of-life models or restricting network access to the management interface may serve as temporary workarounds where patching is not immediately possible. No other mitigations are detailed in the available references [1].
AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.