Description
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
Published: 2026-07-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated remote attacker can execute arbitrary commands on the MA‑T6 device because the firmware fails to correctly verify the origin of a communication channel. The flaw is a classic origin validation vulnerability (CWE‑346) that permits full compromise of the device’s operating system, giving the attacker control over data, configuration and any services running on the device.

Affected Systems

The affected product is the X‑Rite MA‑T6 lab instrument. No specific affected firmware or hardware versions are listed in the advisory; organizations should verify whether their devices run a firmware version prior to any security update from X‑Rite.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread attacks yet. An attacker with network access does not need authentication or privileged access; they can send specially crafted requests that bypass the origin check over the device’s standard communication channels, making the attack trivially feasible and offering full device control.

Generated by OpenCVE AI on July 31, 2026 at 02:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by X‑Rite that addresses the origin validation flaw.
  • If a patch is not yet available, isolate the MA‑T6 by placing it on a dedicated VLAN or firewall zone and blocking all inbound traffic except from explicitly trusted management hosts.
  • Disable any unnecessary remote management protocols and use a dedicated management interface to restrict access to the device.

Generated by OpenCVE AI on July 31, 2026 at 02:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
Title Origin Validation Error in X-Rite MA-T6
First Time appeared X-rite
X-rite ma-t6
Weaknesses CWE-346
CPEs cpe:2.3:a:x-rite:ma-t6:*:*:*:*:*:*:*:*
Vendors & Products X-rite
X-rite ma-t6
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-18T02:46:07.283Z

Reserved: 2023-12-01T08:19:11.319Z

Link: CVE-2023-49899

cve-icon Vulnrichment

Updated: 2026-07-18T02:46:00.856Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:15:06Z

Weaknesses