CVE-2026-26341: Tattile Anpr Mobile Firmware
Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.
Affected products
- Tattile Anpr Mobile Firmware: up to and including 1.181.5
- Tattile Axle Counter Firmware: up to and including 1.181.5
- Tattile Basic MK2 Firmware: up to and including 1.181.5
- Tattile Smart+ Firmware: up to and including 1.181.5
- Tattile Smart+ Speed Firmware: up to and including 1.181.5
- Tattile Smart+ Traffic Light Firmware: up to and including 1.181.5
- Tattile Tolling+ Firmware: up to and including 1.181.5
- Tattile VEGA11 Firmware: up to and including 1.181.5
- Tattile VEGA33 Firmware: up to and including 1.181.5
- Tattile VEGA53 Firmware: up to and including 1.181.5
Published 2026-02-24. Last modified 2026-06-17.