IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Red Lion Controls N-Tron 700 Series

HIGH
CVSS 8.3
Date 2026-10-08T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can cause the switch to reboot by navigating to a specific URL on the device. This action can be scripted on the malicious user's local machine to cause continuous rebooting of the switch.

// Vulnerabilities (7)

CVE ID CVSS Score Severity Description
CVE-2026-33367 8.1 high
SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades-all without any authentication.
CVE-2026-28745 7.5 high
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
CVE-2026-33272 4.9 medium
A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
CVE-2026-29797 7.1 high
No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
CVE-2026-32645 6.0 medium
Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts.
CVE-2026-39460 8.1 high
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.
CVE-2026-39453 8.3 high
Navigating to a certain URL on the switch's web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.

// Remediations (6)

Mitigation: Upgrade to firmware version 3.11.1 or greater
Upgrade to firmware version 3.11.1 or greater
Mitigation: The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here
The advisory issued by HMS Networks regarding these vulnerabilities can be viewed here
Patch: Red Lion controls recommends the following upgrades for the N-Tron 700 Series:
Red Lion controls recommends the following upgrades for the N-Tron 700 Series:
Mitigation: Disable access to the web GUI
Disable access to the web GUI
Mitigation: The upgrade procedure document can be viewed here..
The upgrade procedure document can be viewed here..
Mitigation: Configure or disable the SNMP communities
Configure or disable the SNMP communities

// References