Unauthorized Access in HMS Networks Switches
CVE-2026-33272

6.8MEDIUM

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-33272?

A vulnerability exists in HMS Networks switches that allows a malicious user with physical access to the device to exploit factory settings. By booting the switch without authentication, the attacker can use default administrative credentials to gain full control. This access permits the modification of the configuration file, ensuring that these changes will persist when the device is restarted. Organizations using HMS Networks switches should ensure physical security measures are in place to mitigate this risk.

Affected Version(s)

700 Series 0

700 Series 0

700 Series 3.11.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabrianna (Ria) Milloway of Idaho National Laboratory reported this vulnerability to CISA.
.