CVE-2022-43326: Telosalliance Omnia Mpx Node Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.

Affected products

  • Telosalliance Omnia Mpx Node Firmware: from 1.0.0, before 1.5.0 (fixed in 1.5.0)

Published 2022-11-29. Last modified 2026-06-17.