Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-33272— Red Lion Controls N-Tron 700 Series Authentication Bypass Using an Alternate Path or Channel

Quick assessment

Affected
Red Lion Controls 700 Series
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

具有设备物理访问权限的恶意用户可以在无需身份验证的情况下,将交换机从出厂设置启动,并使用默认的管理凭据获取管理访问权限,同时将更改保存到配置文件中,以便在交换机下次正常启动时这些更改仍然保留。

CVSS 4.9 · Medium

Possible ATT&CK Techniques 1 AI

T1505.003 · Web Shell
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-33272

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Red Lion Controls N-Tron 700 Series Authentication Bypass Using an Alternate Path or Channel
Source: CVE Program / CVE List V5
Vulnerability Description
A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用候选路径或通道进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Lion Controls 700 Series 0 ~ Firmware Versions 3.11.0 -

II. Public POCs for CVE-2026-33272

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-33272

请登录查看更多情报信息。

Other References for CVE-2026-33272 (4)

Same Patch Batch · Red Lion Controls · 2026-10-09 · 7 CVEs total

CVE-2026-39453 8.3 HIGH Red Lion Controls N-Tron 700 Series Reachable Assertion
CVE-2026-39460 8.1 HIGH Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials
CVE-2026-33367 8.1 HIGH Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function
CVE-2026-28745 7.5 HIGH Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format
CVE-2026-29797 7.1 HIGH Red Lion Controls N-Tron 700 Series Download of Code Without Integrity Check
CVE-2026-32645 6.0 MEDIUM Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials

IV. Related Vulnerabilities

V. Comments for CVE-2026-33272

No comments yet


Leave a comment