Zmírněno
15.09.2026
ACR-SA-2026-001: Unauthorized access to the ACR-CV configuration interface
Dotčené produkty:
ACR-CV20, ACR-CV30
Závažnost:
Critical
FW/SW verze:
3.2.0 to 3.4.1
Popis:
The device configuration interface did not verify authorization for selected requests. An attacker with access to the local network could read and modify the configuration without authentication.
Dopad:
Unauthorized modification of the device configuration, with a potential loss of data transmission from the connected meter.
Řešení
Update the firmware to version 3.4.2 or later. Until the update is applied, restrict device access to a trusted network.
Poslední update