Impact
The vulnerability allows an attacker to read and modify internal configuration values, upload and run unsigned applications, and replace firmware and EEPROM data by exploiting exposed debug and engineering services. This improper access control can lead to full compromise of the affected device, granting the attacker control over the motor controller and any connected systems.
Affected Systems
Products affected are Danfoss iC7-Automation SP, iC7-Marine and iC7-Hybrid. The specific firmware revisions prior to the releases 2026.2.5-26A for iC7-Automation SP, 2026.6.30-GR4.4 for iC7-Marine and 2026.7.2-GR4.5 for iC7-Hybrid are vulnerable; exact earlier versions are not listed.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is considered high severity. The EPSS score is not available, and there is no KEV listing, but the exposed service interfaces suggest a remote attack vector where an adversary can interact with the device over the network or via the update mechanism. If exploited, the attacker can upload and execute arbitrary code, effectively taking control of the device.
OpenCVE Enrichment