Impact
The vulnerability is a reachable assertion that causes the device to reboot when a specific URL on its web server is accessed. This failure can be triggered repeatedly with a simple HTTP request, producing a denial‑of‑service condition where the switch is unable to perform any useful function due to constant rebooting. The weakness is categorized as CWE-617, a type of assertion failure that undermines control flow integrity.
Affected Systems
Red Lion Controls N‑Tron 700 Series switches are affected. No version range is specified in the advisory; however the vendor recommends firmware versions 3.11.1 or later for remediation.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. Exploitability is straightforward because any entity that can reach the switch’s web interface can issue the offending request; the attack is local or remote if the web port is exposed. The EPSS score is not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a remote web request to the vulnerable URL.
OpenCVE Enrichment