CVE-2026-27868 PUBLISHED

PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT

Assigner: HackRTU
Reserved: 24.02.2026 Published: 17.06.2026 Updated: 17.06.2026

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information disclosure. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Teldat
Product Regesta Smart HD-PLC - TLDPH16D2
Versions Default: unknown
  • Version 11.02.05.10.02 is affected
  • Version 11.02.06.00.02 is unaffected

Solutions

The provider has implemented the new version  11.02.06.00.02  which solves the security problems detected in the affected version. The end user has to download the new version in the Teldat - Client Support Portal and implement it in the device ( https://support.teldat.com/portal/supportcontent?page=cgs-customer-global-support&none=true&language=en-US ).

Credits

  • Aarón Flecha Menéndez finder
  • Víctor Bello Cuevas finder

References

Problem Types

  • CWE-201 Insertion of sensitive information into sent data CWE

Impacts

  • CAPEC-116 Excavation
  • CAPEC-54 Query System for Information