logo

CISA Issues Alert on ZLAN ICS Flaws Enabling Full Device Takeover

ID: f3524f2b-ccb6-5124-a50e-771231950be6

STIX ID: report--f3524f2b-ccb6-5124-a50e-771231950be6

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Divya

...
...

CISA advisory ICSA-26-041-02 details critical authentication-bypass vulnerabilities in the ZLAN5143D serial-to-Ethernet device server (firmware 1.600) — CVE-2026-25084 and CVE-2026-24789 — rated CVSS 9.8; successful exploitation could allow remote administrative takeover of devices used in industrial control systems, researchers from KPMG reported the issues, and CISA recommends isolating devices from the internet, placing control networks behind firewalls, using secure remote access, and performing impact assessments; no known public exploitation was reported at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.