Improper Signature Verification in Lenze Products Allows Local Attacker SSH Access
CVE-2026-14837

8.5HIGH

Key Information:

Vendor

Lenze

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-14837?

Lenze products are impacted by a vulnerability in the SSH enablement mechanism that results from improper signature verification. This flaw allows a low-privileged local attacker to circumvent the verification process of the SSH enable file signature, potentially granting unauthorized administrative access. If successfully exploited, this access could lead to a complete compromise of the affected systems, endangering the integrity and security of the operational environment.

Affected Version(s)

c430 1.0.0 < 1.15.2

c520 1.0.0 < 1.15.2

c550 1.0.0 < 1.15.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.