VYPR
advisoryPublished Oct 8, 2026· 1 source

CISA Warns of Multiple Vulnerabilities in Red Lion Controls N-Tron 700 Series

CISA has issued an advisory for Red Lion Controls N-Tron 700 Series devices, detailing multiple vulnerabilities that could allow unauthorized administrative access and device reboots.

CISA has released an advisory detailing several critical vulnerabilities affecting Red Lion Controls N-Tron 700 Series industrial network devices. These flaws, identified across firmware versions up to 3.11.0 and bootloader versions up to 2.0.6.1, pose a significant risk to operational technology environments.

The vulnerabilities primarily revolve around insecure credential management and authentication bypass mechanisms. Specifically, CVE-2026-32645 highlights the persistence of default factory credentials with administrative access, even after users have configured new accounts. This means attackers could potentially leverage these known default credentials to gain initial unauthorized access.

Further compounding the risk, CVE-2026-39460 reveals that usernames and passwords, including the default ones, are stored in plaintext within the device's configuration file. This file can be accessed via the Command Line Interface (CLI) or exported through the web interface using TFTP. Alarmingly, this TFTP transfer can be initiated via SNMP without requiring any authentication, providing a straightforward path for attackers to exfiltrate sensitive credentials.

Another vulnerability, CVE-2026-28745, involves the storage of credentials in the configuration file using weak encryption. If an attacker already possesses the default credentials, they could potentially use this weakness to obtain other credentials stored on the system, escalating their privileges.

Beyond credential theft, the vulnerabilities allow for significant disruption. Successful exploitation can grant a malicious user administrative access, enabling them to view, edit, or even upload malicious configuration files. More critically, an attacker can trigger a device reboot by simply navigating to a specific URL. This capability can be scripted to cause continuous denial-of-service by repeatedly rebooting the device, severely impacting industrial operations.

The advisory lists a total of seven vulnerabilities, including Use of Hard-coded Credentials, Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Download of Code Without Integrity Check, Reachable Assertion, and Authentication Bypass Using an Alternate Path or Channel. These vulnerabilities have been assigned CVSS scores indicating a critical severity, with CVSS v3.1 scores reaching up to 8.1 and CVSS v4.0 scores up to 9.3.

Red Lion Controls, a subsidiary of HMS Networks, recommends upgrading affected N-Tron 700 Series devices to firmware version 3.11.1 or greater. Additionally, they advise implementing mitigations such as configuring or disabling SNMP communities, and disabling access to the web GUI if possible. These steps are crucial for protecting industrial control systems from potential compromise and ensuring operational continuity.

Synthesized by Vypr AI