Description
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Published: 2026-02-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

ZLAN Information Technology Co. did not respond to CISA's attempts at coordination. Users of ZLAN5143D devices are encouraged to contact ZLAN and keep their systems up to date. https://www.zlmcu.com/en/contatct_us.htm https://www.zlmcu.com/en/contatct_us.htm

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Zlan Information Technology Co.
Zlan Information Technology Co. zlan5143d
Vendors & Products Zlan Information Technology Co.
Zlan Information Technology Co. zlan5143d

Wed, 11 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 16:45:00 +0000

Type Values Removed Values Added
Description An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Title ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Zlan Information Technology Co. Zlan5143d
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-02-11T16:45:23.479Z

Reserved: 2026-01-29T21:07:29.858Z

Link: CVE-2026-24789

cve-icon Vulnrichment

Updated: 2026-02-11T16:45:13.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T17:16:13.040

Modified: 2026-02-11T18:06:04.010

Link: CVE-2026-24789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-11T21:37:47Z

Weaknesses