CVE-2026-24789Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Disclousure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-11); latest day: 2
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-11: 3Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-16: 2Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-11: 3Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-16: 202-1102-1202-1302-16
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
Disclousure
114.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-113
Disclosure3
2026-02-121
Disclosure1
2026-02-131
Patch1
2026-02-162
Disclousure1Patch1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Disclousure

    CISA warns of critical ZLAN5143D flaws CVE-2026-25084 & CVE-2026-24789. Attackers can bypass login & reset passwords. Isolate devices now. #ZLAN #CISA #ICS #OTSecurity #CyberSecurity #CVE202625084 #IndustrialIoT https://securityonline.info/critical-zlan5143d-flaws-cvss-9-8-allow-total-takeover-no-patch-available/

    Post summary

    CISA has issued a warning about critical ZLAN5143D flaws that allow attackers to bypass login and reset passwords; no patch is available yet.

    00020354
    10.3K followersView on X
  • NerdieNews@NewsNerdie
    Patch

    Today's Top Cybersecurity News – February 13, 2026 1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited. Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/ 2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution. Sources: Cvefeed, Microsoft https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/ 3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2019-25335 4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks. Sources: Cvefeed, Feedburner, Securityaffairs https://cvefeed.io/vuln/detail/CVE-2024-50619 5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25084 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The post reports several critical vulnerabilities across various software, providing technical details and emphasizing immediate patching, with no evidence of active exploitation or PoC.

    0001056
    54 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24789 Unauthenticated Remote Password Change Vulnerability in Target Device API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24789

    Post summary

    The text announces CVE‑2026‑24789 as an unauthenticated remote password change vulnerability in a target device API and directs readers to a vulnerability details page.

    0001048
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24789 An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. https://www.cve.org/CVERecord?id=CVE-2026-24789

    Post summary

    The CVE identifies an unprotected API endpoint that lets an attacker remotely change a device password without any authentication.

    00010262
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-24789 - Critical An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. https://www.thehackerwire.com/vulnerability/CVE-2026-24789/ https://t.co/GIY3iIKAFN

    Post summary

    CVE-2026-24789 exposes an unprotected API endpoint that lets attackers change device passwords without authentication, posing a critical security risk.

    1000058
    112 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA Warns: Critical ZLAN5143D ICS Bugs Allow Full Device Takeover (CVSS 9.8) CISA advisory ICSA-26-041-02 flags two critical ZLAN5143D serial-to-Ethernet flaws—CVE-2026-25084 (missing auth) and CVE-2026-24789 (auth bypass/password reset)—that enable unauthenticated remote admin control on firmware v1.600. This matters because these devices often bridge IT/OT in manufacturing, so compromise can become a lateral-movement pivot into control networks; isolate from the internet, segment OT, and patch/monitor immediately. 🎯 Target: Global/Manufacturing & ICS/OT #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/zlan-ics-flaws/

    Post summary

    CISA issued a warning about two critical ZLAN5143D flaws that allow unauthenticated remote administration, urging immediate patching and network isolation.

    0000030
    176 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24789: CRITICAL] An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.#cve,CVE-2026-24789,#cybersecurity https://cvefind.com/CVE-2026-24789

    Post summary

    The post discloses CVE‑2026‑24789, a critical vulnerability enabling unauthenticated device password changes via an unprotected API endpoint; no PoC, exploit, or patch details are provided.

    0000066
    583 followersView on X

Explore more