Description
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
Published: 2026-07-27
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, classified as CWE-347, is an improper signature verification in the SSH enablement mechanism. A local attacker who has low privilege can bypass the signature check, enable SSH, and gain administrative access, which can lead to full system compromise.

Affected Systems

Lenze devices c430, c520, c550, i950 GenA and i950 GenB are affected. The issue applies to all firmware releases of the c4xx, c5xx and i950 families.

Risk and Exploitability

The CVSS score is 8.5 and the EPSS score is < 1%, but the vulnerability is not listed in the CISA KEV catalog. The attack is likely carried out locally through privilege escalation; after enabling SSH, the attacker can remotely access the device and perform arbitrary actions.

Generated by OpenCVE AI on August 3, 2026 at 17:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Retrieve and install the latest firmware update from Lenze that fixes the signature verification issue.
  • Disable or strongly restrict local accounts that have low privilege and ensure only authorized users can access SSH.
  • Configure firewall or network segmentation to limit external access to the device and monitor logs for attempts to enable SSH or for abnormal authentication events.

Generated by OpenCVE AI on August 3, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Lenze c430
Lenze c550
Lenze i950 Gena
Lenze i950 Genb
Vendors & Products Lenze c430
Lenze c550
Lenze i950 Gena
Lenze i950 Genb

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
Title SSH Enablement Signature Verification Bypass
First Time appeared Lenze
Lenze c4xx Firmware
Lenze c5xx Firmware
Lenze i950 Firmware
Weaknesses CWE-347
CPEs cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:*
Vendors & Products Lenze
Lenze c4xx Firmware
Lenze c5xx Firmware
Lenze i950 Firmware
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenze C430 C4xx Firmware C550 C5xx Firmware I950 Firmware I950 Gena I950 Genb
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-27T14:01:50.573Z

Reserved: 2026-07-06T09:59:37.390Z

Link: CVE-2026-14837

cve-icon Vulnrichment

Updated: 2026-07-27T14:01:45.944Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T08:16:17.463

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-14837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature