CVE-2026-0647: Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulnerabilities
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the device’s embedded web server’s availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the embedded web server is not required, disable the device's web interface to remove the vulnerable management surface.
1794-AENTR adapter embedded web server web_interface_enabled = false - Compensating control
Restrict network access to the 1794-AENTR adapter's web interface and management ports using firewall rules, VLANs, and ACLs so only trusted management IPs/networks can reach it. Where possible, use a WAF or network filter to block the specific HTTP GET requests targeting the vulnerable endpoint.
- Operational
If there is any chance the device was exposed or compromised, rotate administrative web-interface credentials, review device logs for unauthorized access or configuration changes, and isolate the device until remediation is complete.
- Operational
Monitor Rockwell Automation advisories and apply any vendor-supplied firmware updates or patches for the 1794-AENTR adapter as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0647?
The severity of CVE-2026-0647 is high with a CVSS score of 8.8.
How do I fix CVE-2026-0647?
To fix CVE-2026-0647, update the Rockwell Automation FLEX I/O 1794-AENTR adapter firmware to the latest version provided by Rockwell Automation.
What type of vulnerability is CVE-2026-0647?
CVE-2026-0647 is an improper authentication vulnerability affecting the web server of the device.
Who is affected by CVE-2026-0647?
Users of the Rockwell Automation FLEX I/O 1794-AENTR adapter are affected by CVE-2026-0647.
What can an attacker do with CVE-2026-0647?
An attacker can change the web interface password of the device without authentication by exploiting CVE-2026-0647.