Authentication Bypass Vulnerability in MR-GM5L-S1 and MR-GM5A-L1 Devices by MR-Lab
CVE-2026-27842

9.3CRITICAL

Key Information:

Vendor
CVE Published:
11 March 2026

What is CVE-2026-27842?

A serious vulnerability has been identified in MR-GM5L-S1 and MR-GM5A-L1 devices manufactured by MR-Lab. This authentication bypass issue can potentially allow malicious actors to circumvent authentication mechanisms, enabling unauthorized access to device configuration settings. Exploitation of this flaw can lead to significant security risks, including manipulation of device operations and compromise of user data.

Affected Version(s)

MR-GM5A-L1 firmware versions prior to v2.01.04N1_02

MR-GM5L-S1 firmware versions prior to v2.01.04N1_02

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.