CVE-2026-1632 PUBLISHED

RISS SRL MOMA Seismic Station Missing Authentication for Critical Function

Assigner: icscert
Reserved: 29.01.2026 Published: 03.02.2026 Updated: 03.02.2026

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor RISS SRL
Product MOMA Seismic Station
Versions Default: unaffected
  • affected from 0 to Version v2.4.2520 (incl.)

Workarounds

RISS SRL did not respond to CISA's request for coordination. Users of RISS MOMA Seismic Station are encouraged to contact RISS SRL (info@riss-srl.com) for more information.

Credits

  • Souvik Kandar reported this vulnerability to CISA finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE