ZeroHour

CVE-2026-82787

niche

Missing Authentication Lets Remote Attackers Operate CPSL-08P1EN Devices

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CPSL-08P1EN is affected by a missing authentication for critical function vulnerability (CWE-306), rated high severity with a CVSS v4.0 base score of 8.7. A remote attacker who can reach the affected product over the network can invoke a critical function without supplying valid credentials and operate the device as if they were an authorized user. The CVSS vector indicates high impact on the device's confidentiality, integrity, and availability, meaning an attacker could potentially read, alter, or disrupt its operation. Organizations running CPSL-08P1EN units whose network management/control interface is reachable from untrusted networks or the internet are the most exposed. As of this writing, no public proof-of-concept is known, there are no confirmed reports of exploitation in the wild, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Restrict network access to CPSL-08P1EN devices so that the vulnerable management/control interface is reachable only from a trusted management VLAN or over a VPN, and never expose it directly to the internet. Check the vendor's security page and the JPCERT/CC (JVN) advisory for a firmware update and apply it as soon as one is released. Until patched, monitor the device's logs and network traffic for unauthenticated commands or unexpected configuration changes.

Affected
CPSL-08P1EN
Estimated exposure
nichelikely hundreds to low thousands of devices (single niche hardware model) — The advisory covers a single model of a niche hardware appliance coordinated through JPCERT/CC in Japan, with no public install counts or internet-wide scan data available, so deployment is assumed to be small.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.