CVE-2026-18808
—Unauthenticated Code Injection in Klemsan KIO (Klemsan Internet Objects)
KIO (Klemsan Internet Objects) from Klemsan Electrical Electronics Inc. contains a code injection flaw (CWE-94) affecting all versions before v1.9. The vulnerability is reachable over the network without credentials or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so a remote attacker can trigger it directly against the affected system. Successful code injection can allow execution of attacker-controlled code with high impact to confidentiality, integrity, and availability, effectively amounting to unauthenticated remote code compromise. Any organization or operator running KIO prior to v1.9 is affected. No public proof-of-concept, CISA KEV listing, or reported in-the-wild exploitation is currently known, and EPSS estimates only a 0.4% probability of exploitation within the next 30 days.
What to do: Upgrade KIO to v1.9 or later, which resolves the code injection flaw. Until upgraded, verify whether any KIO instances are exposed to the internet and restrict access via firewall rules or VPN to reduce the unauthenticated network attack surface. There is no indication of active exploitation, but patching should be prioritized given the critical (9.8) unauthenticated severity.
| Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) | all versions before v1.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.