CVE-2026-26341Disclosure(tattile / anpr_mobile)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tattile anpr_mobile systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.

1.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-1392

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • anpr_mobile
  • anpr_mobile_firmware
  • axle_counter
  • axle_counter_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
anpr_mobileanpr_mobile_firmwareaxle_counteraxle_counter_firmwarebasic_mk2basic_mk2_firmwaresmart\+smart\+_firmwaresmart\+_speedsmart\+_speed_firmware

1 version affected across 20 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-25: 3Mentions · 2026-02-26: 1Mentions · 2026-03-22: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-22: 1Technical Details · 2026-02-25: 3Technical Details · 2026-02-26: 1Technical Details · 2026-03-22: 102-2502-2603-22
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-02-261
Disclosure1
2026-03-221
Patch1
Full discourse5 posts
  • White Rabbitx@TheRabbitPy
    Patch

    🚨 CVE-2026-26341 (CVSS 9.8): Firefox iOS address-bar desync lets malicious pages spoof any domain—perfect for phishing on mobile. Update ASAP. https://nvd.nist.gov/vuln/detail/CVE-2026-26341

    Post summary

    The tweet highlights a new high‑severity Firefox iOS vulnerability (CVE‑2026‑26341, CVSS 9.8) that can spoof domain names, and urges users to update promptly to prevent phishing.

    0203078
    374 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26341 - Critical Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. A... https://www.thehackerwire.com/vulnerability/CVE-2026-26341/ https://t.co/zuV22ytVRR

    Post summary

    The post announces CVE-2026-26341, noting that certain Tattile device firmware versions ship with default credentials that are not required to be changed, potentially exposing them to unauthorized access.

    0000046
    119 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26341 Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installatio… https://www.cve.org/CVERecord?id=CVE-2026-26341

    Post summary

    The CVE discloses that Tattile Smart+, Vega, and Basic device families ship with default credentials that are not required to be changed during installation, exposing a credential management flaw.

    00000125
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26341 Default Credentials Vulnerability in Tattile Smart+ Devices Firmware 1.181.5 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26341

    Post summary

    A default credentials vulnerability has been disclosed for Tattile Smart+ devices firmware 1.181.5 and earlier, with no mention of PoC, exploit, patch, or active exploitation.

    0000042
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: Default creds in Tattile Smart+, Vega, Basic devices (fw ≤1.181.5) allow admin takeover if exposed online. Act now: change passwords, restrict access! 🔒 https://radar.offseq.com/threat/cve-2026-26341-cwe-1392-use-of-default-credentials-b1797eea #OffSeq #IoTSecurity... https://t.co/DkgksKb4V6

    Post summary

    A critical vulnerability (CVE-2026-26341) in Tattile Smart+ and related devices allows admin takeover via default credentials; users are urged to change passwords and restrict access.

    0000034
    270 followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
HWtattileanpr_mobile---
OStattileanpr_mobile_firmware---
HWtattileaxle_counter---
OStattileaxle_counter_firmware---
HWtattilebasic_mk2---
OStattilebasic_mk2_firmware---
HWtattilesmart\+---
OStattilesmart\+_firmware---
HWtattilesmart\+_speed---
OStattilesmart\+_speed_firmware---
HWtattilesmart\+_traffic_light---
OStattilesmart\+_traffic_light_firmware---
HWtattiletolling\+---
OStattiletolling\+_firmware---
HWtattilevega11---
OStattilevega11_firmware---
HWtattilevega33---
OStattilevega33_firmware---
HWtattilevega53---
OStattilevega53_firmware---

Explore more