CVE-2026-33367

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Referenced assets1 URL
By indicator
Full discourse1 post
  • ♫Why♥Not♪@Python_s_

    #NØØT_Security_Alerts 🚨 #ALERT — CRITICAL SECURITY FLAWS EXPOSE RED LION INDUSTRIAL SWITCHES TO UNAUTHORIZED ADMINISTRATIVE OPERATIONS October 8, 2026 PRODUCT: Red Lion Controls N-Tron 700 Series CVE: CVE-2026-33367, CVE-2026-29797 SEVERITY: High — Critical infrastructure risk AFFECTED VERSIONS: Firmware 3.11.0 and earlier; bootloader 2.0.6.1 and earlier. IMPACT: CISA identifies seven vulnerabilities affecting industrial network switches. Missing authentication in SNMP functionality can expose configuration files, permit unauthorized administrative changes, and enable firmware or bootloader modifications. Additional flaws expose credentials and allow service disruption. EXPLOITATION STATUS: CONFIRMED VULNERABILITIES. CISA reports no known public exploitation. Actual compromise remains unverified. Forensic triage: Investigate suspicious SNMP/TFTP activity, unauthorized configuration exports, firmware changes, and unexpected switch reboots. URGENT ACTION: Upgrade to firmware 3.11.1 or later. Restrict switch management access, configure or disable SNMP communities, and disable unnecessary web management. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01 CONFIDENCE: VERY HIGH — Official CISA industrial control systems advisory ICSA-26-281-01. #CyberSecurity #ThreatIntel #ICS #OTSecurity #IndustrialSecurity #NetworkSecurity #NØØT

    0000020
    229 followersView on X

Explore more