Description
A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
Published: 2026-10-09
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Authentication bypass allowing unauthorized configuration and persistent control
Action: Apply Firmware Upgrade
AI Analysis

Impact

A physical attacker can reset the device to factory defaults, bypassing all authentication, and then use the factory default administrative credentials to gain privileged access. The attacker can then save configuration changes that persist across normal boots, enabling long‑term unauthorized control of the switch. This flaw is an Improper Authentication weakness (CWE-288) that can lead to unauthorized configuration, service disruption, or potential lateral movement within the network.

Affected Systems

Products affected are Red Lion Controls N-Tron 700 Series switches running firmware versions earlier than 3.11.1. Red Lion Controls recommends upgrading to firmware 3.11.1 or newer, configuring or disabling SNMP communities, and disabling access to the web GUI to mitigate the issue.

Risk and Exploitability

The CVSS score is 6.8, with no EPSS score available and no listing in the CISA KEV catalog. The vulnerability requires physical access to the device and booting from factory settings, so it is a local attack. Despite its moderate severity, an attacker with physical access can maintain persistent administrative privileges. The official resolution is to upgrade firmware and disable vulnerable services.

Generated by OpenCVE AI on October 9, 2026 at 16:39 UTC.

Remediation

Vendor Solution

Red Lion controls recommends the following upgrades for the N-Tron 700 Series: * Upgrade to firmware version 3.11.1 or greater * Configure or disable the SNMP communities * Disable access to the web GUI The upgrade procedure document can be viewed here https://www.hms-networks.com/ . The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here https://www.hms-networks.com/cybersecurity .


OpenCVE Recommended Actions

  • Upgrade firmware to version 3.11.1 or newer per Red Lion Controls guidance
  • Configure or disable SNMP communities to reduce unsecured access
  • Disable access to the web GUI to shrink the attack surface

Generated by OpenCVE AI on October 9, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
Title Red Lion Controls N-Tron 700 Series Authentication Bypass Using an Alternate Path or Channel
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-09T14:44:26.429Z

Reserved: 2026-04-08T19:28:49.636Z

Link: CVE-2026-33272

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:14.173

Modified: 2026-10-09T17:29:33.410

Link: CVE-2026-33272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T16:45:09Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel