Description
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
Published: 2026-10-09
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a reachable assertion that causes the device to reboot when a specific URL on its web server is accessed. This failure can be triggered repeatedly with a simple HTTP request, producing a denial‑of‑service condition where the switch is unable to perform any useful function due to constant rebooting. The weakness is categorized as CWE-617, a type of assertion failure that undermines control flow integrity.

Affected Systems

Red Lion Controls N‑Tron 700 Series switches are affected. No version range is specified in the advisory; however the vendor recommends firmware versions 3.11.1 or later for remediation.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. Exploitability is straightforward because any entity that can reach the switch’s web interface can issue the offending request; the attack is local or remote if the web port is exposed. The EPSS score is not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a remote web request to the vulnerable URL.

Generated by OpenCVE AI on October 9, 2026 at 16:54 UTC.

Remediation

Vendor Solution

Red Lion controls recommends the following upgrades for the N-Tron 700 Series: * Upgrade to firmware version 3.11.1 or greater * Configure or disable the SNMP communities * Disable access to the web GUI The upgrade procedure document can be viewed here https://www.hms-networks.com/ . The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here https://www.hms-networks.com/cybersecurity .


OpenCVE Recommended Actions

  • Upgrade firmware to version 3.11.1 or newer
  • Configure or disable SNMP communities as recommended by the vendor
  • Disable or block access to the web GUI

Generated by OpenCVE AI on October 9, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
Title Red Lion Controls N-Tron 700 Series Reachable Assertion
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-09T14:42:18.998Z

Reserved: 2026-04-08T19:28:49.591Z

Link: CVE-2026-39453

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:14.500

Modified: 2026-10-09T17:29:33.410

Link: CVE-2026-39453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:00:09Z

Weaknesses