CVE-2026-22911

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
15/01/2026
Last modified:
23/01/2026

Description

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sick:tdc-x401gl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:tdc-x401gl:-:*:*:*:*:*:*:*