CISA Issues Alert on ZLAN ICS Flaws Enabling Full Device Takeover
ID: f3524f2b-ccb6-5124-a50e-771231950be6
STIX ID: report--f3524f2b-ccb6-5124-a50e-771231950be6
Feed Name: GBHackers
CISA advisory ICSA-26-041-02 details critical authentication-bypass vulnerabilities in the ZLAN5143D serial-to-Ethernet device server (firmware 1.600) — CVE-2026-25084 and CVE-2026-24789 — rated CVSS 9.8; successful exploitation could allow remote administrative takeover of devices used in industrial control systems, researchers from KPMG reported the issues, and CISA recommends isolating devices from the internet, placing control networks behind firewalls, using secure remote access, and performing impact assessments; no known public exploitation was reported at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
