CVE-2026-3356 PUBLISHED

Missing Authentication for Critical Function vulnerability in Anritsu Remote Spectrum Monitor

Assigner: icscert
Reserved: 27.02.2026 Published: 31.03.2026 Updated: 01.04.2026

The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Anritsu
Product Remote Spectrum Monitor MS27100A
Versions Default: unaffected
  • Version All versions is affected
Vendor Anritsu
Product Remote Spectrum Monitor MS27101A
Versions Default: unaffected
  • Version All versions is affected
Vendor Anritsu
Product Remote Spectrum Monitor MS27102A
Versions Default: unaffected
  • Version All versions is affected
Vendor Anritsu
Product Remote Spectrum Monitor MS27103A
Versions Default: unaffected
  • Version All versions is affected

Workarounds

Anritsu has no plans to fix this issue. Anritsu recommends that users deploy Remote Spectrum Monitor within secure network environments to mitigate potential risks.

Users can contact Anritsu Technical Support (1-800-267-4878) for more information.

Credits

  • Souvik Kandar reporter

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE