CVE-2026-70403: Critical severity XING CPTrans-ME-X vulnerability
Published Sep 4, 2026
·Updated
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
Affected Software
1 affected component
XING CPTrans-ME-X
Event History
Sep 4, 2026
CVE Published
via MITRE·06:31 AM
Data Sourced
via MITRE·06:31 AM
DescriptionSeverity
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs knowledge of the hard-coded credential. The issue can then allow login to an affected device without requiring prior privileges or user interaction.
2
Can this be exploited remotely?
The supplied severity vector indicates network attack access with low complexity. This means devices reachable over a network are the relevant exposure scenario.
3
What impact could successful exploitation have?
The supplied severity vector rates confidentiality, integrity, and availability impact as high. A successful login using the hard-coded credential could therefore expose the affected device to significant compromise.