CVE-2026-39453: Red Lion Controls N-Tron 700 Series Reachable Assertion
Published Oct 9, 2026
·Updated
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
Affected Software
1 affected component
Red Lion Controls N-Tron 700 Series
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Lion Controls N-Tron 700 Seriesto a version that resolves this vulnerability.Fixed in 3.11.1 - Configuration
Configure or disable the SNMP communities.
Red Lion Controls N-Tron 700 Series SNMP communities = configured or disabled - Configuration
Disable access to the web GUI.
Red Lion Controls N-Tron 700 Series web GUI web GUI access = disabled
Event History
Oct 9, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The issue is network-reachable and requires low privileges. No user interaction is required.
2
What is the operational impact of exploitation?
Requesting a specific URL on the switch web server causes the switch to reboot. An attacker can automate repeated requests, such as with curl, to keep the device rebooting and create a denial-of-service condition.