CISA ICS advisories warn of critical authentication and RCE flaws in industrial and IoT devices
CISA published multiple ICS advisories warning of high-severity vulnerabilities affecting industrial/IoT products deployed in critical infrastructure environments. For Jinan USR IOT Technology (PUSR) USR-W610 (<= 3.1.1.0), CISA reported multiple issues (including CVE-2026-25715, CVE-2026-24455, CVE-2026-26049, CVE-2026-26048) that could allow authentication to be effectively disabled (e.g., permitting blank admin credentials over the web interface and Telnet), enable credential exposure (including administrator credentials), and cause denial-of-service; one of the cited conditions results in full administrative control for a network-adjacent attacker without valid credentials (CVSS v3.1 9.8). Separately, EnOcean SmartServer IoT (<= 4.60.009) was reported vulnerable to OS command execution via crafted LON IP-852 management messages (CVE-2026-20761) and an additional weakness that could leak memory and help bypass mitigations such as ASLR (CVE-2026-22885) (CVSS v3.1 8.1).
CISA also warned that Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller is affected by CVE-2026-24790 (missing authentication for a critical function), where the underlying PLC can be remotely influenced without proper safeguards, creating risk of over- or under-odorization events (CVSS v3.1 8.2). In parallel reporting, a separate CISA warning covered Honeywell CCTV products impacted by CVE-2026-1670 (CVSS 9.8), where an unauthenticated API endpoint could allow an attacker to change the “forgot password” recovery email and take over accounts to access camera feeds; at the time of reporting, there were no public exploitation reports, and CISA recommended reducing exposure (e.g., isolating devices behind firewalls and using secure remote access).

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
CISA publishes advisory on Welker OdorEyes XL4 Controller vulnerability
CISA published an ICS advisory for CVE-2026-24790 affecting the Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller. The missing-authentication flaw could allow remote influence of the underlying PLC and potentially cause over-odorization or under-odorization events; CISA said there was no known public exploitation at the time of publication.
CISA publishes advisory on PUSR USR-W610 router vulnerabilities
CISA published an ICS advisory covering multiple vulnerabilities in Jinan USR IOT Technology Limited's USR-W610 Wi-Fi router affecting versions up to and including 3.1.1.0. Reported by researchers from Payatu Security Consulting, the issues included authentication bypass, credential exposure, plaintext password disclosure, and Wi-Fi deauthentication/disassociation denial of service, with no known public exploitation reported at publication.
CISA publishes advisory on EnOcean SmartServer IoT vulnerabilities
CISA published an ICS advisory for two vulnerabilities in EnOcean Edge Inc's EnOcean SmartServer IoT affecting version 4.60.009 and earlier. The flaws, reported by Amir Zaltzman of Claroty Team82, could enable command injection and an out-of-bounds read, and CISA said there was no known public exploitation at publication.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Jinan USR IOT Technology Limited (PUSR) USR-W610 | CISA
cisa.gov
Open sourceEnOcean SmartServer IoT | CISA
cisa.gov
Open sourceWelker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller | CISA
cisa.gov
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


