2026-02-03 23:2CVE-2026-1633icscert
PUBLISHED5.2CWE-306

Synectix LAN 232 TRIO Missing Authentication for Critical Function

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.

Problem type

Affected products

Synectix

LAN 232 TRIO

All versions - AFFECTED

References

GitHub Security Advisories

GHSA-wr22-69c2-f45v

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface...

https://github.com/advisories/GHSA-wr22-69c2-f45v

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-1633
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-1633",
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "dateUpdated": "2026-02-03T23:02:58.208Z",
    "dateReserved": "2026-01-29T16:19:22.805Z",
    "datePublished": "2026-02-03T23:02:58.208Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert",
        "dateUpdated": "2026-02-03T23:02:58.208Z"
      },
      "datePublic": "2026-02-03T19:00:00.000Z",
      "title": "Synectix LAN 232 TRIO Missing Authentication for Critical Function",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Synectix",
          "product": "LAN 232 TRIO",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "All versions",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-306 Missing Authentication for Critical Function",
              "cweId": "CWE-306",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04"
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-034-04.json"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "CHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 10,
            "baseSeverity": "CRITICAL"
          }
        },
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "workarounds": [
        {
          "lang": "en",
          "value": "The affected products should be considered end-of-life, as Synectix is \nno longer in business and therefore firmware fixes, mitigations and \nupdates will be unavailable.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "The affected products should be considered end-of-life, as Synectix is \nno longer in business and therefore firmware fixes, mitigations and \nupdates will be unavailable.\n\n<br>"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Souvik Kandar of MicroSec reported this vulnerability to CISA",
          "type": "finder"
        }
      ]
    }
  }
}