CVE-2026-16731
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
06/08/2026
Last modified:
06/08/2026
Description
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients.<br />
An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network.



