Authentication Bypass Vulnerability in MR-GM5L-S1 and MR-GM5A-L1 Devices by MR-Lab
CVE-2026-27842
9.3CRITICAL
What is CVE-2026-27842?
A serious vulnerability has been identified in MR-GM5L-S1 and MR-GM5A-L1 devices manufactured by MR-Lab. This authentication bypass issue can potentially allow malicious actors to circumvent authentication mechanisms, enabling unauthorized access to device configuration settings. Exploitation of this flaw can lead to significant security risks, including manipulation of device operations and compromise of user data.
Affected Version(s)
MR-GM5A-L1 firmware versions prior to v2.01.04N1_02
MR-GM5L-S1 firmware versions prior to v2.01.04N1_02
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
