PT-2026-21790 · Tattile · Basic+2
Gjoko Krstic
·
Publicado
2026-02-24
·
Atualizado
2026-02-27
·
CVE-2026-26342
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tattile Smart+, Vega, and Basic device families versions 1.181.5 and prior
Description
The affected devices implement an authentication token (
X-User-Token) with insufficient expiration. An attacker who obtains a valid token, for example through interception, log exposure, or token reuse on a shared system, can continue to authenticate to the management interface until the token is revoked. This enables unauthorized access to device functions and data.Recommendations
Versions prior to 1.181.5 should be updated.
Exploit
Correção
Insufficient Session Expiration
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Basic
Tattile Smart+
Vega