# CVE-2026-25086

## Summary

- **CVE ID:** CVE-2026-25086
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-605
- **Published:** Mar 20, 2026
- **Last Modified:** Mar 23, 2026

## Description

Under certain conditions, an attacker could bind to the same port used 
by WebCTRL. This could allow the attacker to craft and send malicious 
packets and impersonate the WebCTRL service without requiring code 
injection into the WebCTRL software.

## Affected Products

- Automated Logic — WebCTRL Premium Server (0)

## References

- [CNA](https://www.automatedlogic.com/en/company/security-commitment/)
- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-08)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-078-08.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._