Unauthenticated Remote Access Vulnerability in Affected Devices by Vendor
CVE-2026-35075

9.3CRITICAL

Key Information:

Vendor

Mbs

Vendor
CVE Published:
3 June 2026

What is CVE-2026-35075?

An unauthorized remote attacker can exploit a flaw that allows recovery of a default, hard-coded password embedded in the firmware image of the affected devices. This vulnerability poses a significant security risk, enabling attackers to gain complete control over the devices without authentication. Users are strongly advised to review firmware settings and implement necessary updates to prevent unauthorized access.

Affected Version(s)

Double-A Profibus V1_0_0_0

Double-A x-link V1_0_0_0

Double-X CAN V1_0_0_0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
.