Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilityembedded-device-vulnerabilityidentity-authentication-vulnerabilitycritical-infrastructure-threat

CISA ICS advisories warn of critical authentication and RCE flaws in industrial and IoT devices

Updated 3mo agoFirst seen Feb 19, 20263 sources

CISA published multiple ICS advisories warning of high-severity vulnerabilities affecting industrial/IoT products deployed in critical infrastructure environments. For Jinan USR IOT Technology (PUSR) USR-W610 (<= 3.1.1.0), CISA reported multiple issues (including CVE-2026-25715, CVE-2026-24455, CVE-2026-26049, CVE-2026-26048) that could allow authentication to be effectively disabled (e.g., permitting blank admin credentials over the web interface and Telnet), enable credential exposure (including administrator credentials), and cause denial-of-service; one of the cited conditions results in full administrative control for a network-adjacent attacker without valid credentials (CVSS v3.1 9.8). Separately, EnOcean SmartServer IoT (<= 4.60.009) was reported vulnerable to OS command execution via crafted LON IP-852 management messages (CVE-2026-20761) and an additional weakness that could leak memory and help bypass mitigations such as ASLR (CVE-2026-22885) (CVSS v3.1 8.1).

CISA also warned that Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller is affected by CVE-2026-24790 (missing authentication for a critical function), where the underlying PLC can be remotely influenced without proper safeguards, creating risk of over- or under-odorization events (CVSS v3.1 8.2). In parallel reporting, a separate CISA warning covered Honeywell CCTV products impacted by CVE-2026-1670 (CVSS 9.8), where an unauthenticated API endpoint could allow an attacker to change the “forgot password” recovery email and take over accounts to access camera feeds; at the time of reporting, there were no public exploitation reports, and CISA recommended reducing exposure (e.g., isolating devices behind firewalls and using secure remote access).

Share:
CISA ICS advisories warn of critical authentication and RCE flaws in industrial and IoT devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 19, 20264mo ago

CISA publishes advisory on Welker OdorEyes XL4 Controller vulnerability

CISA published an ICS advisory for CVE-2026-24790 affecting the Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller. The missing-authentication flaw could allow remote influence of the underlying PLC and potentially cause over-odorization or under-odorization events; CISA said there was no known public exploitation at the time of publication.

CISA publishes advisory on PUSR USR-W610 router vulnerabilities

CISA published an ICS advisory covering multiple vulnerabilities in Jinan USR IOT Technology Limited's USR-W610 Wi-Fi router affecting versions up to and including 3.1.1.0. Reported by researchers from Payatu Security Consulting, the issues included authentication bypass, credential exposure, plaintext password disclosure, and Wi-Fi deauthentication/disassociation denial of service, with no known public exploitation reported at publication.

CISA publishes advisory on EnOcean SmartServer IoT vulnerabilities

CISA published an ICS advisory for two vulnerabilities in EnOcean Edge Inc's EnOcean SmartServer IoT affecting version 4.60.009 and earlier. The flaws, reported by Amir Zaltzman of Claroty Team82, could enable command injection and an out-of-bounds read, and CISA said there was no known public exploitation at publication.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.