- Community aggregator
- Country: United States
CVE-2026-94293: AAS Edge Client — CVSS 9.8 IIoT Data Tampering, No Patch, Decommission Now
CVE-2026-94293 (CVSS 9.8) — Murrelektronik's Software AAS Edge Client exposes an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read all AAS submodel data via GET and overwrite it via PATCH — no credentials, no user interaction, no exploit…