CVE-2025-13926Disclosure

LOWCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-807

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-09: 4Mentions · 2026-04-10: 1Active Exploitation · 2026-04-09: 1Technical Details · 2026-04-09: 4Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-094
Active Exploitation1Disclosure3
2026-04-101
Disclosure1
Full discourse5 posts
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 CRITICAL: CVE-2025-13926 (CVSS 9.8) - Contemporary Controls BASC 20T vulnerable to packet forgery via network sniffing. Attackers can make arbitrary requests with no authentication required. #CVE #PatchNow #ThreatIntel https://t.co/qV2MqMFP1x

    Post summary

    The tweet announces CVE-2025-13926, a high‑severity packet‑forgery vulnerability in Contemporary Controls BASC 20T, with no evidence of active exploitation or a provided patch.

    00000385
    10 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-13926: CRITICAL] An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.#cve,CVE-2025-13926,#cybersecurity https://cvefind.com/CVE-2025-13926

    Post summary

    The tweet announces CVE-2025-13926, a critical vulnerability that allows attackers to sniff traffic and forge packets to send arbitrary requests to Contemporary Controls BASC 20T devices.

    00000123
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13926 An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T. https://www.cve.org/CVERecord?id=CVE-2025-13926

    Post summary

    CVE-2025-13926 discloses that an attacker can sniff traffic and forge packets to send arbitrary requests to a Contemporary Controls BASC 20T device; no PoC, exploit, patch, or evidence of active exploitation is stated.

    00000175
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-13926: Contemporary Controls BASC 20T R... Network sniffing leads to complete system takeover on industrial controllers - packet forgery bypasses all auth with ze... https://zerodaysignal.com/vulnerability/CVE-2025-13926 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces CVE‑2025‑13926, describing how network sniffing coupled with packet forgery can bypass authentication and allow full takeover of Contemporary Controls BASC 20T controllers, with no active exploitation or patch noted.

    00000318
    204 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploiting CVE-2025-13926 can intercept network traffic to forge packets and execute arbitrary requests against Contemporary Controls BASC-20T industrial controllers. This enables device reconfiguration, file manipulation, and remote procedure calls. Runtime segmentation helps contain such post-compromise lateral movement in OT environments. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/contemporary-controls-basc-20t-vulnerability-2026

    Post summary

    CVE-2025-13926 is being actively exploited to intercept traffic, forge packets, and manipulate device functions on Contemporary Controls BASC‑20T industrial controllers, with no patch or mitigation described.

    00000290
    1.9K followersView on X

Explore more