CVE-2026-32666

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate.
Configurations

No configuration.

History

17 Jun 2026, 10:36

Type Values Removed Values Added
Summary
  • (es) Los sistemas WebCTRL que se comunican a través de BACnet heredan la falta de autenticación de capa de red del protocolo. WebCTRL no implementa validación adicional del tráfico BACnet, por lo que un atacante con acceso a la red podría falsificar paquetes BACnet dirigidos tanto al servidor WebCTRL como a los controladores AutomatedLogic asociados. Los paquetes falsificados pueden ser procesados como legítimos.

21 Mar 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 00:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32666

Mitre link : CVE-2026-32666

CVE.ORG link : CVE-2026-32666


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing