CVE-2023-36669: Kratosdefense Ngc Indoor Unit Firmware

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.

Affected products

  • Kratosdefense Ngc Indoor Unit Firmware: before 11.4 (fixed in 11.4)

Published 2023-07-18. Last modified 2026-06-17.