Rockwell 1715-AENTR exposes unauthenticated debug port
A Rockwell Automation 1715-AENTR EtherNet/IP Adapter flaw exposes an unauthenticated debug CLI that could let attackers read/delete files or alter I/O states.
CISA has published an advisory for CVE-2026-10577 affecting Rockwell Automation's 1715-AENTR EtherNet/IP Adapter, versions 3.003 and earlier. The vulnerability stems from a network-accessible debug port that lacks proper authentication controls, allowing unauthenticated remote attackers to issue intrusive command-line interface commands against the device.
Successful exploitation could allow an attacker to read or delete files, stop running tasks, modify memory, and change I/O states, impacting confidentiality, integrity, and availability of the affected device. The product is deployed worldwide across energy, water/wastewater, and critical manufacturing sectors. Rockwell recommends upgrading to version 3.011 or later, and CISA has issued standard ICS network segmentation and access-control guidance. No known public exploitation has been reported at this time.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free