CVE-2026-39460: Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Lion Controls N-Tron 700 Series firmwareto a version that resolves this vulnerability.Fixed in 3.11.1 - Configuration
Configure or disable the SNMP communities.
Red Lion Controls N-Tron 700 Series SNMP communities = configured or disabled - Configuration
Disable access to the web GUI.
Red Lion Controls N-Tron 700 Series web GUI access = disabled
Event History
Frequently Asked Questions
What access does an attacker need to obtain the stored credentials?
An attacker with administrator rights can view the configuration through the CLI or export it through the web interface. Separately, an unauthenticated attacker can initiate a TFTP transfer through SNMP.
Are default credentials exposed as well as user-created credentials?
Yes. The configuration file stores usernames and passwords in plaintext, including the default factory credentials.
What interfaces should be restricted if patching is not immediately possible?
Restrict access to SNMP, TFTP, the web interface, and CLI administration paths. In particular, prevent unauthorized SNMP access because it can initiate a TFTP configuration transfer without authentication.