CVE-2026-2330 - CVE-2026-2330

CVE-2026-2330 - CVE-2026-2330

CVE ID : CVE-2026-2330 Published : March 6, 2026, 8:16 a.m. | 1 hour, 42 minutes ago Description : An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
March 6, 2026
Attack Vector: network