CVE-2026-33272: Red Lion Controls N-Tron 700 Series Authentication Bypass Using an Alternate Path or Channel
A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Lion Controls N-Tron 700 Seriesto a version that resolves this vulnerability.Fixed in 3.11.1 - Configuration
Configure or disable the SNMP communities.
SNMP SNMP communities = configured or disabled - Configuration
Disable access to the web GUI.
N-Tron 700 Series web GUI web GUI access = disabled
Event History
Frequently Asked Questions
Who can exploit this issue?
A malicious user needs physical access to an affected N-Tron 700 Series switch. The issue does not describe remote exploitation.
What access can an attacker obtain?
The attacker can boot the switch using factory settings, authenticate with the default administrative credentials, and gain administrative access.
Will the attacker’s changes survive a normal reboot?
Yes. After gaining administrative access, the attacker can save configuration changes so they persist when the switch next boots normally.