CVE-2026-4436: Gpl Odorizers GPL750 XL4

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

Affected products

  • Gpl Odorizers GPL750 XL4: from v1.0, before v6.0 (fixed in v6.0)
  • Gpl Odorizers GPL750 XL4 Prime: from v4.0, before v6.0 (fixed in v6.0)
  • Gpl Odorizers Gpl Odorizers GPL750 XL7: from v13.0, before v20.0 (fixed in v20.0)
  • Gpl Odorizers Gpl Odorizers GPL750 XL7 Prime: from v18.4, before v20.0 (fixed in v20.0)

Published 2026-04-09. Last modified 2026-06-17.