ZeroHour

CVE-2026-18808

Unauthenticated Code Injection in Klemsan KIO (Klemsan Internet Objects)

CVSS 3.1
9.8 critical
EPSS
<1%p32
Published
()
Modified
AI analysis

KIO (Klemsan Internet Objects) from Klemsan Electrical Electronics Inc. contains a code injection flaw (CWE-94) affecting all versions before v1.9. The vulnerability is reachable over the network without credentials or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so a remote attacker can trigger it directly against the affected system. Successful code injection can allow execution of attacker-controlled code with high impact to confidentiality, integrity, and availability, effectively amounting to unauthenticated remote code compromise. Any organization or operator running KIO prior to v1.9 is affected. No public proof-of-concept, CISA KEV listing, or reported in-the-wild exploitation is currently known, and EPSS estimates only a 0.4% probability of exploitation within the next 30 days.

What to do: Upgrade KIO to v1.9 or later, which resolves the code injection flaw. Until upgraded, verify whether any KIO instances are exposed to the internet and restrict access via firewall rules or VPN to reduce the unauthenticated network attack surface. There is no indication of active exploitation, but patching should be prioritized given the critical (9.8) unauthenticated severity.

Affected
Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects)all versions before v1.9
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.