VORANT. Threat Intelligence Research Sign in Create a free account

CISA Warns of N-Tron 700 Series Flaws

routine vulnerability manufacturingtelecommunicationstechnologyinfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CISA advisory details seven vulnerabilities in Red Lion N-Tron 700 Series switches allowing admin access and remote reboot via hard-coded credentials and auth bypass.

CISA published an ICS advisory (ICSA-26-281-01) detailing seven vulnerabilities affecting Red Lion Controls N-Tron 700 Series industrial switches, impacting firmware versions 3.11.0 and earlier and bootloader versions 2.0.6.1 and earlier. The flaws stem from hard-coded credentials, insufficiently protected credentials, passwords stored in recoverable format, missing authentication for critical functions, download of code without integrity checks, reachable assertions, and authentication bypass via an alternate path or channel.

Successful exploitation could allow an attacker to gain administrative access to the device, enabling them to view, edit, and upload configuration files. A malicious actor can also trigger a device reboot by navigating to a specific URL, and this action can be scripted to cause continuous, repeated rebooting of the switch — a denial-of-service condition affecting network availability for critical infrastructure environments. The affected products are deployed worldwide across Commercial Facilities, Communications, Critical Manufacturing, and Information Technology sectors.

Red Lion Controls (a subsidiary headquartered via HMS Networks, Sweden) recommends upgrading to firmware version 3.11.1 or later, configuring or disabling SNMP communities, and disabling access to the web GUI where not needed. CISA additionally recommends standard ICS hardening practices: minimizing network exposure for control system devices, isolating them from business networks, and using VPNs for remote access where required. No public exploitation of these vulnerabilities has been reported. The issues were responsibly disclosed to CISA by a researcher at Idaho National Laboratory.

Mentioned in this report

Vulnerabilities CVE-2026-28745CVE-2026-29797CVE-2026-32645CVE-2026-33272CVE-2026-33367CVE-2026-39453CVE-2026-39460

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,090 reports from 148 sources, 491 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs