CVE-2026-29797: Red Lion Controls 700 Series
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
Affected products
- Red Lion Controls 700 Series
Published 2026-10-09. Last modified 2026-10-09.