{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/red-lion-controls/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["N-Tron 700 Series (\u003c=Firmware_3.11.0)","N-Tron 700 Series (\u003c=Bootloader_2.0.6.1)"],"_cs_severities":["high"],"_cs_tags":["industrial-control-systems","ot-security","vulnerability-management"],"_cs_type":"advisory","_cs_vendors":["Red Lion Controls"],"content_html":"\u003cp\u003eRed Lion Controls N-Tron 700 series industrial switches are affected by a suite of seven vulnerabilities (CVE-2026-32645, CVE-2026-39460, CVE-2026-28745, CVE-2026-33367, CVE-2026-29797, CVE-2026-39453, CVE-2026-33272) that compromise the integrity and availability of the devices. These flaws range from hard-coded factory credentials to improper storage of plaintext passwords in configuration files and missing authentication for critical functions such as TFTP transfers initiated via SNMP. An attacker can leverage these weaknesses to gain full administrative control over the switch, modify configuration files, or induce continuous reboots by navigating to specific URLs on the device. Given their deployment in critical infrastructure, including communication and manufacturing sectors, these vulnerabilities present a significant risk of lateral movement, network disruption, and credential exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants unauthorized administrative access, enabling adversaries to extract sensitive network configuration credentials stored in plaintext or weakly encrypted formats. Furthermore, the ability to trigger a continuous reboot condition leads to persistent denial-of-service, disrupting critical communication flows. The vulnerability affects N-Tron 700 series switches globally across commercial facilities, IT, and manufacturing environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate the risk of exploitation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade N-Tron 700 Series firmware to version 3.11.1 or greater immediately to remediate the vulnerabilities listed in ICSA-26-281-01.\u003c/li\u003e\n\u003cli\u003eDisable access to the web GUI on all N-Tron 700 Series devices to prevent unauthorized configuration access and DoS URL exploitation.\u003c/li\u003e\n\u003cli\u003eDisable or restrict access to SNMP communities, particularly those allowing unauthenticated command execution or TFTP initialization.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate industrial switch management interfaces from broader organizational networks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T17:06:13Z","date_published":"2026-10-08T17:06:13Z","id":"https://feed.craftedsignal.io/briefs/2026-10-red-lion-n-tron-vulnerabilities/","summary":"Multiple high and critical severity vulnerabilities in Red Lion Controls N-Tron 700 series switches, including hard-coded credentials and improper authentication, allow for unauthorized administrative access, configuration theft, and denial-of-service.","title":"Multiple Vulnerabilities in Red Lion Controls N-Tron 700 Series","url":"https://feed.craftedsignal.io/briefs/2026-10-red-lion-n-tron-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Red Lion Controls","version":"https://jsonfeed.org/version/1.1"}