CVE-2026-82786
nicheRecoverable credentials in backup files of IAI Remote I/O Coupler CPSN-MCB271
An insufficiently protected credentials flaw (CWE-522) exists in the Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* from IAI Corporation, in which sensitive information such as login credentials is stored in an inadequately protected form inside backup files generated from the device. An unauthenticated remote attacker who obtains a backup file — for example by downloading it from the network-accessible server-type coupler or by acquiring a copy that was shared or stored elsewhere — can restore the file and extract the embedded sensitive information. Successful exploitation exposes confidential data, most plausibly device or network credentials, which could then be reused for unauthorized access to the coupler or to other systems; the CVSS 4.0 vector (VC:H, VI:N, VA:N) indicates a confidentiality-only impact on the vulnerable component. Affected parties are factories, machine builders, and OEMs that deploy IAI CPSN-MCB271-* remote I/O couplers and generate or retain configuration backup files from them. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and no exploitation in the wild has been reported.
What to do: Check IAI's advisory for updated firmware and apply it to every CPSN-MCB271-* server-type coupler, since the CVE data does not name a patched version. Treat all backup files generated from these units as containing recoverable credentials: encrypt and restrict where they are stored, delete obsolete copies, and change any credentials contained in backups that have left your control. Ensure these couplers are not reachable from the internet by placing them on an isolated OT network segment behind a firewall or VPN.
| IAI Corporation Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | All models in the CPSN-MCB271-* series (no specific fixed or unaffected version is identified in the CVE data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.