CVE-2026-25086
Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-605
- Published
- 2026-03-20
- Last modified
- 2026-03-23
Affected products
- Automated Logic WebCTRL Premium Server
Weakness type
Related vulnerabilities
- CVE-2025-15320 — Tanium addressed a denial of service vulnerability in Tanium Client.
- CVE-2024-30218 — Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform