# Rockwell 1715-AENTR exposes unauthenticated debug port

Published: 2026-07-14 · Severity: high · Sectors: energy, manufacturing, infrastructure
Canonical: https://vorant.io/reports/d56b2176-1dde-571a-a800-4d93f977b30e/rockwell-1715-aentr-exposes-unauthenticated-debug-port

> A Rockwell Automation 1715-AENTR EtherNet/IP Adapter flaw exposes an unauthenticated debug CLI that could let attackers read/delete files or alter I/O states.

CISA has published an advisory for CVE-2026-10577 affecting Rockwell Automation's 1715-AENTR EtherNet/IP Adapter, versions 3.003 and earlier. The vulnerability stems from a network-accessible debug port that lacks proper authentication controls, allowing unauthenticated remote attackers to issue intrusive command-line interface commands against the device.

Successful exploitation could allow an attacker to read or delete files, stop running tasks, modify memory, and change I/O states, impacting confidentiality, integrity, and availability of the affected device. The product is deployed worldwide across energy, water/wastewater, and critical manufacturing sectors. Rockwell recommends upgrading to version 3.011 or later, and CISA has issued standard ICS network segmentation and access-control guidance. No known public exploitation has been reported at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2026-10577

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d56b2176-1dde-571a-a800-4d93f977b30e/rockwell-1715-aentr-exposes-unauthenticated-debug-port.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
