CVE-2026-32645: Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials
Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Lion Controls N-Tron 700 Series firmwareto a version that resolves this vulnerability.Fixed in 3.11.1 - Configuration
Configure or disable the SNMP communities.
Red Lion Controls N-Tron 700 Series SNMP communities = configured or disabled - Configuration
Disable access to the web GUI.
Red Lion Controls N-Tron 700 Series web GUI access = disabled
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to the affected N-Tron 700 Series device and high privileges, according to the supplied CVSS vector. The issue does not require user interaction.
Do configured administrator accounts remove the exposure?
No. The factory administrative credentials remain enabled even after other administrator accounts are configured.
What access could an attacker gain?
The hard-coded factory credentials provide administrative access. The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact indicated.