CVE-2026-24789 PUBLISHED

ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function

Assigner: icscert
Reserved: 29.01.2026 Published: 11.02.2026 Updated: 11.02.2026

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor ZLAN Information Technology Co.
Product ZLAN5143D
Versions Default: unaffected
  • Version v1.600 is affected

Workarounds

ZLAN Information Technology Co. did not respond to CISA's attempts at coordination. Users of ZLAN5143D devices are encouraged to contact ZLAN and keep their systems up to date. https://www.zlmcu.com/en/contatct_us.htm

https://www.zlmcu.com/en/contatct_us.htm

Credits

  • Shorabh Karir and Deepak Singh of KPMG reported these vulnerabilities to CISA finder

References

Problem Types

  • CWE-306 CWE