Improper Authentication in NewType WebEIP Affects Remote Access
CVE-2026-18610

6.9MEDIUM

Key Information:

Vendor

Newtype

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-18610?

A vulnerability has been identified in NewType WebEIP versions up to 3.0, specifically in the file /EIP_Com_FileList.aspx. This flaw facilitates improper authentication, potentially allowing unauthorized access. The vulnerability can be exploited remotely, raising significant concerns regarding the security of user data. Despite attempts to inform the vendor, there has been no response regarding this issue, which is now publicly available for exploitation.

Affected Version(s)

WebEIP 3.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ox882 (VulDB User)
VulDB CNA Team
.