Impact
A physical attacker can reset the device to factory defaults, bypassing all authentication, and then use the factory default administrative credentials to gain privileged access. The attacker can then save configuration changes that persist across normal boots, enabling long‑term unauthorized control of the switch. This flaw is an Improper Authentication weakness (CWE-288) that can lead to unauthorized configuration, service disruption, or potential lateral movement within the network.
Affected Systems
Products affected are Red Lion Controls N-Tron 700 Series switches running firmware versions earlier than 3.11.1. Red Lion Controls recommends upgrading to firmware 3.11.1 or newer, configuring or disabling SNMP communities, and disabling access to the web GUI to mitigate the issue.
Risk and Exploitability
The CVSS score is 6.8, with no EPSS score available and no listing in the CISA KEV catalog. The vulnerability requires physical access to the device and booting from factory settings, so it is a local attack. Despite its moderate severity, an attacker with physical access can maintain persistent administrative privileges. The official resolution is to upgrade firmware and disable vulnerable services.
OpenCVE Enrichment