PT-2026-23659 · Crown · Crown

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2026-2330

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions CROWN versions (affected versions not specified)
Description An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters. The vulnerability allows modification of critical device settings via the CROWN REST interface. The vulnerable component is the whitelist enforcement mechanism within the CROWN REST interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2330

Affected Products

Crown