Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple High‑Severity Auth Bypass & Credential Flaws in Red Lion N‑Tron 700 Series Switches

Seven critical vulnerabilities in Red Lion N‑Tron 700 series switches allow unauthenticated admin access, configuration tampering, and scripted reboot loops. The flaws expose gaps in authentication and change‑management controls that auditors and regulators scrutinize for trust‑worthiness.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

Multiple High‑Severity Auth Bypass & Credential Flaws in Red Lion N‑Tron 700 Series Switches (CVE‑2026‑32645, CVE‑2026‑39460, CVE‑2026‑28745, CVE‑2026‑33367, CVE‑2026‑29797, CVE‑2026‑39453, CVE‑2026‑33272)

What It Is – Seven vulnerabilities affect the N‑Tron 700 series firmware and bootloader, including hard‑coded credentials, insecure password storage, missing authentication for critical functions, and an authentication‑bypass path. Successful exploitation grants an attacker administrative access, the ability to edit or upload configuration files, and the power to trigger a reboot loop via a crafted URL.

Exploitability – The flaws are publicly disclosed, have CVSS v3.1 base scores of 8.3 (High), and can be exploited remotely without prior access. No public proof‑of‑concept is required beyond sending a crafted HTTP request.

Affected Products – Red Lion Controls N‑Tron 700 Series switches (firmware ≤ 3.11.0, bootloader ≤ 2.0.6.1).

Why It Matters for Trust & Control Assurance

  • Authentication & Authorization – Hard‑coded or recoverable credentials break the fundamental control that limits privileged access, a core requirement across most governance frameworks.
  • Configuration Integrity – Unauthenticated configuration uploads undermine evidence of change‑management and make audit trails unreliable.
  • Continuous Monitoring – Detecting unauthorized reboots or config changes requires real‑time logging and alerting to maintain a defensible audit record for regulators and enterprise buyers.

Recommended Actions

  • Apply Red Lion’s firmware/bootloader patches immediately.
  • Replace any default or hard‑coded credentials with unique, strong passwords and store them using a salted hash.
  • Enforce multi‑factor authentication for all privileged accounts on the device.
  • Enable immutable logging of configuration changes and reboot events; integrate logs into a SIEM for continuous monitoring.
  • Conduct a post‑patch validation to confirm that the authentication controls are effective.

Source: CISA Advisory – ICSA‑26‑281‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →