ZeroHour

CVE-2026-77974

Missing Authentication in Device Firmware Update Channel (CVE-2026-77974)

CVSS 4.0
8.5 high
EPSS
<1%p5
Published
()
Modified
AI analysis

CVE-2026-77974 is a missing-authentication flaw (CWE-306) in a firmware update mechanism, assigned by CISA ICS-CERT; the source data does not name the affected vendor or product. An attacker positioned on an adjacent network who spoofs the device to the application and obtains a single user confirmation may be able to cause the application to transmit firmware over an unauthenticated and unsigned update channel, potentially delivering attacker-controlled or unverified firmware to the device. The CVSS 4.0 score of 8.5 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable system, with no privileges required and only one user action needed. Exposure cannot be quantified from the available data because no product, version range, or install-base figures are provided, though the ICS-CERT assignment suggests an industrial or IoT-style device deployment. There is no evidence of exploitation in the wild and no public proof-of-concept is known.

What to do: Check the CISA ICS-CERT advisory for CVE-2026-77974 to confirm the affected product and version range, then apply the vendor's patched application or firmware as soon as it is published. Until patched, restrict adjacent-network access to the device (e.g., pairing range or local network segment), treat any unsolicited firmware-update prompt with suspicion, and verify that the update channel enforces signed and authenticated firmware.

Affected
Device companion application with firmware update function
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.

Weakness
CWE-306
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.