CVE-2026-2330

Critical
|9.4
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

An attacker can gain unauthorized access to sensitive areas of a device's filesystem, allowing them to upload harmful files that can change important settings, like network configurations, after a reboot. This vulnerability occurs because some internal directories meant for testing are not properly protected, meaning an attacker doesn't need to log in to exploit it.

Technical Description

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$9,000($5K-$15K)
Vendor Response
Grade APatched in 3 days

Quick Information

Published

Mar 6, 2026

about 1 month ago

Last Modified

Mar 9, 2026

about 1 month ago