logo

Roaring Access: Exploiting a Pre-Auth Root RCE on Sixnet RTUs

ID: 1bdb7715-425e-58e9-b6b4-830f95586246

STIX ID: report--1bdb7715-425e-58e9-b6b4-830f95586246

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2025-11-12

Date Updated: 2026-04-17

Author: Nitsan Litov

...
...

Team82 discloses two critical vulnerabilities (CVE-2023-42770) in Red Lion Sixnet RTUs (SixTRAK and VersaTRAK) where the Sixnet Universal protocol's TCP handling bypasses UDP-based authentication on port 1594, allowing unauthenticated remote execution of shell commands as root; Red Lion and CISA have published advisories and patches, and organizations are urged to apply updates and block TCP access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.