Insecure Default Credentials in NI grpc-device Affecting Network Security
CVE-2026-9142
9.3CRITICAL
What is CVE-2026-9142?
The NI grpc-device is impacted by a vulnerability that arises when TLS configuration is absent and the server is accessible beyond the loopback interface. This flaw enables unauthorized users to potentially gain access to the server on the local network, posing significant security risks. Products affected include versions 2.17.0 and earlier, which should be reviewed and updated promptly to prevent exploitation.
Affected Version(s)
grpc-device 0 <= 2.17.0
InstrumentStudio 0 <= 26.3.0
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sebastián Alba Vives (@Sebasteuo / 0xS4bb1)
