CVE-2026-28745: Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Lion Controls N-Tron 700 Seriesto a version that resolves this vulnerability.Fixed in 3.11.1 - Configuration
Configure or disable the SNMP communities.
SNMP SNMP communities = configured or disabled - Configuration
Disable access to the web GUI.
Red Lion Controls N-Tron 700 Series Web GUI access = disabled
Event History
Frequently Asked Questions
What does an attacker need to recover other credentials from an affected device?
The attacker needs knowledge of the default credentials. With those credentials, they could obtain other usernames and passwords stored in the configuration file because they are protected with weak encryption.
Are default credentials relevant to this issue?
Yes. The advisory specifically states that default credentials are among the usernames and passwords stored in the configuration file, and knowing them can enable recovery of other credentials on the system.