CVE-2026-2330Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Patch: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-0603-1003-11
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure2General2
2026-03-101
Patch1
2026-03-111
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    SICK PSIRT warns of critical vulnerabilities (CVE-2026-2330, CVE-2026-2331) in Lector85x and Lector83x scanners allowing full device takeover. Update now #SICKLector #CVE20262331 #ICSSecurity #CyberSecurity #IndustrialAutomation #Vulnerability #PatchAlert https://securityonline.info/critical-9-8-cvss-flaws-expose-sick-lector-scanners-to-hijacking/ https://t.co/WdJPqdaQYs

    Post summary

    The post warns of critical device‑takeover vulnerabilities in SICK Lector scanners and urges users to apply updates, but it does not provide PoC, exploit code, or evidence of current exploitation.

    01010333
    10.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2330 (CVSS:9.4, CRITICAL) is Awaiting Analysis. An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis..https://nvd.nist.gov/vuln/detail/CVE-2026-2330 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical CVE (CVE‑2026‑2330) with potential filesystem access via a CROWN REST interface, but contains no PoC, exploit, or patch information.

    0000039
    172 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2330 An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for … https://www.cve.org/CVERecord?id=CVE-2026-2330

    Post summary

    The notice reports that CVE-2026-2330 allows unauthorized filesystem access via the CROWN REST interface due to incomplete whitelist enforcement, with no mention of PoC, exploit code, active exploitation, or patch information.

    00000121
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2330: CRITICAL] Vulnerability alert: Incomplete whitelist enforcement in CROWN REST interface allows unauthenticated attackers to access restricted directories and modify critical device settings. St...#cve,CVE-2026-2330,#cybersecurity https://cvefind.com/CVE-2026-2330

    Post summary

    The post announces CVE-2026-2330 as a critical issue, detailing that incomplete whitelist enforcement in the CROWN REST interface enables unauthenticated attackers to access restricted directories and alter device settings. No PoC, exploit code, active exploitation claims, or patch information are provided.

    00000100
    597 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2330 Intel Report: https://ift.tt/HwZA6Qe

    Post summary

    A brief alert references CVE-2026-2330 and includes a link to an intel report, but provides no additional details.

    0000038
    343 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2330 - Critical An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing wer... https://www.thehackerwire.com/vulnerability/CVE-2026-2330/ https://t.co/uwLE4Oq1JP

    Post summary

    CVE‑2026‑2330 exposes a flaw in the CROWN REST interface that lets attackers read restricted filesystem locations, thanks to incomplete whitelist checks.

    0000048
    125 followersView on X

Explore more