CVE-2026-3893
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
28/04/2026
Last modified:
28/04/2026
Description
The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, <br />
allowing an attacker with network access to directly access and modify <br />
its configuration and operational functions without needing credentials.
Impact
Base Score 3.x
9.40
Severity 3.x
CRITICAL



