CVE-2026-3893

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
28/04/2026
Last modified:
28/04/2026

Description

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, <br /> allowing an attacker with network access to directly access and modify <br /> its configuration and operational functions without needing credentials.