Description
A low-privileged remote attacker can send Modbus packets to manipulate
register values that are inputs to the odorant injection logic such that
too much or too little odorant is injected into a gas line.
Published: 2026-04-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Control System Manipulation via Unauthorized Modbus Register Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability permits a low‑privileged attacker who can send Modbus packets to the GPL750-based odorizers to alter register values that control odorant injection. By modifying these values, the attacker can cause the device to inject either too much or too little odorant into a gas line, compromising the intended masking of hazardous substances and potentially exposing personnel and the environment to harmful conditions. The weakness corresponds to CWE‑306, missing authentication for a critical control function.

Affected Systems

Affected devices are the GPL Odorizers GPL750 series, specifically the XL4, XL4 Prime, XL7, and XL7 Prime models. Firmware updates—Horner Automation version 15.76 for the XL series and version 17.30 for the XL Prime series—are available through the vendor’s repository. Administrators should remove older firmware files from the device’s microSD card, retaining only the LOGS folder and the FIRMWARE.LIC file if a WebMI license is used. The compressed update package can be extracted to the root of the microSD card, or technicians can provide preconfigured SD cards if management lacks IT permissions.

Risk and Exploitability

The impact is rated moderate to high with a CVSS score of 8.6. EPSS data is not provided and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote Modbus communication over the device’s network interface or serial link; this inference is based on the description’s mention of Modbus packet manipulation. Exploitation requires only low‑privilege access to the Modbus network, making the threat realistic in environments where these devices are not protected by network segmentation or authentication.

Generated by OpenCVE AI on April 9, 2026 at 21:20 UTC.

Remediation

Vendor Solution

GPL Odorizers recommends users update to the latest software version of the GPL750 in connection with the latest firmware from Horner Automation for the XL4, XL4 Prime, XL7, and XL7 Prime devices.https://lincenergysystems-my.sharepoint.com/:f:/p/h_baer/IgDYaHIhXpyLQJvnKPd6b80TAUgV7Lp8qmVYBFUb0lmr7ak?e=JLeADm. https://lincenergysystems-my.sharepoint.com/:f:/p/h_baer/IgDYaHIhXpyLQJvnKPd6b80TAUgV7Lp8qmVYBFUb0lmr7ak?e=JLeADm


OpenCVE Recommended Actions

  • Update the GPL750 firmware to the latest version provided by GPL Odorizers and Horner Automation, using firmware 15.76 for XL series or 17.30 for XL Prime series.
  • Clear existing firmware files from the device’s microSD card, keeping only the LOGS folder and the FIRMWARE.LIC file if a WebMI license exists.
  • If users lack IT permissions, obtain preconfigured SD cards from GPL Odorizers and swap them into the odorizers prior to installation.
  • Contact GPL Odorizers support (phone 303‑697‑6701) for assistance or verification that the patch was applied correctly.

Generated by OpenCVE AI on April 9, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Gpl Odorizers
Gpl Odorizers gpl750 (xl4)
Gpl Odorizers gpl750 (xl4 Prime)
Gpl Odorizers gpl Odorizers Gpl750 (xl7)
Gpl Odorizers gpl Odorizers Gpl750 (xl7 Prime)
Vendors & Products Gpl Odorizers
Gpl Odorizers gpl750 (xl4)
Gpl Odorizers gpl750 (xl4 Prime)
Gpl Odorizers gpl Odorizers Gpl750 (xl7)
Gpl Odorizers gpl Odorizers Gpl750 (xl7 Prime)

Thu, 09 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.
Title GPL Odorizers GPL750 Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Gpl Odorizers Gpl750 (xl4) Gpl750 (xl4 Prime) Gpl Odorizers Gpl750 (xl7) Gpl Odorizers Gpl750 (xl7 Prime)
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-04-14T14:04:53.417Z

Reserved: 2026-03-19T19:21:21.967Z

Link: CVE-2026-4436

cve-icon Vulnrichment

Updated: 2026-04-14T14:04:19.698Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-09T20:16:27.903

Modified: 2026-06-17T10:56:34.090

Link: CVE-2026-4436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:29:22Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function