CVE-2026-3323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
28/04/2026
Last modified:
11/05/2026

Description

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:vega:vegapuls_6x_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:o:vega:vegapuls_6x_firmware:1.1.0:*:*:*:*:*:*:*
cpe:2.3:h:vega:vegapuls_6x:-:*:*:*:*:*:*:*