Description
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-06
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Insta's InstaKNXServiceApp firmware update handler allows an attacker to bypass data authenticity checks when the CreateWebClientAndDownloadFileList function is invoked. Based on the description, it is inferred that the attacker may be able to tamper with the firmware update payload, potentially leading to compromised device integrity or availability. The weakness is identified as CWE‑345, indicating insufficient verification of data authenticity.

Affected Systems

Insta's InstaKNXServiceApp, specifically version 1.2.3.1469, is impacted. No other versions or products are listed.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity assessment. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely documented exploitation yet. The attack vector is remote, but the description notes that exploitation is highly complex and difficult, which may reduce the likelihood of an immediate real‑world attack.

Generated by OpenCVE AI on August 7, 2026 at 01:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release that includes the security fix once it becomes available
  • Configure the firmware update mechanism to enforce strict authenticity checks, such as digital signature or hash verification
  • Restrict or disable remote firmware updates to authorized users only, ensuring that all update channels are verified
  • Monitor event logs for suspicious firmware download or update activity

Generated by OpenCVE AI on August 7, 2026 at 01:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Title Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList data authenticity
First Time appeared Insta
Insta instaknxserviceapp
Weaknesses CWE-345
CPEs cpe:2.3:a:insta:instaknxserviceapp:*:*:*:*:*:*:*:*
Vendors & Products Insta
Insta instaknxserviceapp
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Insta Instaknxserviceapp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T17:00:09.377Z

Reserved: 2026-08-06T08:29:01.612Z

Link: CVE-2026-19061

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T02:00:06Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity