在更新固件或引导加载程序时,无需进行身份验证,这使得恶意文件很容易被推送到设备中。此外,任何拥有相同软件的人都可以扫描网络上的 N-Tron 设备,并通过使用 SNMP/TFTP 推送或拉取固件,而无需进行身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Lion Controls | 700 Series | 0 ~ Firmware Versions 3.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39453 | 8.3 HIGH | Red Lion Controls N-Tron 700 Series Reachable Assertion |
| CVE-2026-39460 | 8.1 HIGH | Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials |
| CVE-2026-33367 | 8.1 HIGH | Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function |
| CVE-2026-28745 | 7.5 HIGH | Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format |
| CVE-2026-32645 | 6.0 MEDIUM | Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials |
| CVE-2026-33272 | 4.9 MEDIUM | Red Lion Controls N-Tron 700 Series Authentication Bypass Using an Alternate Path or Chann |
No comments yet