Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-11841

CVSS 9.4 · Critical EPSS 0.46% · P37

Affected Version Matrix 5

VendorProductVersion RangeStatus
SICK AGInspectorP61x< 5.4.0affected
SICK AGInspectorP62x< 5.4.0affected
SICK AGInspectorP63xall versionsaffected
SICK AGInspectorP64xall versionsaffected
SICK AGInspectorP65xall versionsaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-11841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-11841
Source: CVE Program / CVE List V5
Vulnerability Description
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对外部实体的文件或目录可访问
Source: CVE Program / CVE List V5
Vulnerability Title
SICK AG InspectorP61x 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SICK AG InspectorP61x是SICK AG公司的一款自动化控制检测设备。 SICK AG InspectorP61x 5.4.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于访问限制不当,导致未经身份验证的攻击者通过HTTP进行文件访问,可读写敏感文件系统区域,包括设备参数文件,并可执行任意Lua代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SICK AGInspectorP61x 0 ~ 5.4.0 -
SICK AGInspectorP62x 0 ~ 5.4.0 -
SICK AGInspectorP65x all versions -
SICK AGInspectorP63x all versions -
SICK AGInspectorP64x all versions -

II. Public POCs for CVE-2026-11841

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11841

登录查看更多情报信息。

Vendor Advisories for CVE-2026-11841 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-11841

No comments yet


Leave a comment