CVE-2026-22907: Critical severity SICK Tdc-x401gl Firmware vulnerability
Published Jan 15, 2026
·Updated
An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
Affected Software
2 affected components
All of the following
SICK Tdc-x401gl Firmware<1.4.0
SICK Tdc-x401gl
Remediation
Information
Users are strongly recommended to upgrade to the latest release of TDC-X401GL (>= 1.4.0).
Event History
Jan 15, 2026
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 20, 58071
Event
via FIRST·09:47 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-22907?
CVE-2026-22907 has a high severity rating due to the potential for unauthorized access to the host filesystem.
2
How do I fix CVE-2026-22907?
To fix CVE-2026-22907, update the SICK Tdc-x401gl firmware to version 1.4.0 or later.
3
What type of access does CVE-2026-22907 allow?
CVE-2026-22907 allows an attacker to gain unauthorized access to the host filesystem.
4
Which software is affected by CVE-2026-22907?
CVE-2026-22907 affects the SICK Tdc-x401gl firmware versions prior to 1.4.0.
5
Is the SICK Tdc-x401gl hardware affected by CVE-2026-22907?
The SICK Tdc-x401gl hardware itself is not vulnerable; the vulnerability lies in specific firmware versions.