CVE-2026-24448Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-11); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-15: 1Mentions · 2026-05-11: 2Technical Details · 2026-03-11: 2Technical Details · 2026-03-15: 1Technical Details · 2026-05-11: 103-1103-1505-11
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure1General1
2026-03-151
Disclosure1
2026-05-112
Disclosure1General1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-24448 CVSS: 9.8 (3.0) — CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-24448 with a high CVSS score and critical severity, but contains no evidence of exploitation, PoC, or patch.

    1000031
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-24448-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text references a link to an advisory for CVE-2026-24448 but includes no explicit details on proof of concept, exploitation, patches, or technical characteristics.

    0000022
    188 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24448 Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access. https://www.cve.org/CVERecord?id=CVE-2026-24448

    Post summary

    CVE-2026-24448 exposes hard‑coded credentials in MR‑GM5L‑S1 and MR‑GM5A‑L1, potentially enabling attackers to gain administrative access. No PoC, exploit code, or patch is mentioned.

    00000174
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-24448 - Critical Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access. https://www.thehackerwire.com/vulnerability/CVE-2026-24448/ https://t.co/fM78FR81GF

    Post summary

    The post reports CVE‑2026‑24448 as a hard‑coded credential flaw in specific devices that could grant admin access, but provides no PoC, exploit details, or remediation information.

    0000033
    134 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24448: CRITICAL] Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.#cve,CVE-2026-24448,#cybersecurity https://cvefind.com/CVE-2026-24448

    Post summary

    A critical vulnerability involving hard‑coded credentials in MR‑GM5L‑S1 and MR‑GM5A‑L1 devices, capable of granting administrative access, has been disclosed.

    0000031
    601 followersView on X

Explore more