Impact
An unauthenticated remote attacker can execute arbitrary commands on the MA‑T6 device because the firmware fails to correctly verify the origin of a communication channel. The flaw is a classic origin validation vulnerability (CWE‑346) that permits full compromise of the device’s operating system, giving the attacker control over data, configuration and any services running on the device.
Affected Systems
The affected product is the X‑Rite MA‑T6 lab instrument. No specific affected firmware or hardware versions are listed in the advisory; organizations should verify whether their devices run a firmware version prior to any security update from X‑Rite.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread attacks yet. An attacker with network access does not need authentication or privileged access; they can send specially crafted requests that bypass the origin check over the device’s standard communication channels, making the attack trivially feasible and offering full device control.
OpenCVE Enrichment