Status: UPDATED
| Advisory ID: CVE-2026-0647
Key Details
| CVE | CVE-2026-0647 |
| CVSS Score / Version | 8.8 (High) / CVSS v4.0 |
| Updated | 2026-06-17 |
| Affected products | Rockwell Automation FLEX I/O EtherNet/IP Adapters |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the device’s embedded web server’s availability. (NVD)
What to Do
Monitor Rockwell Automation's web page for any future patch releases.
References