PT-2026-34742 · Carlson · Vasco-B Gnss Receiver

Souvik Kandar

·

Published

2026-04-23

·

Updated

2026-04-28

·

CVE-2026-3893

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Carlson VASCO-B GNSS Receiver (affected versions not specified)
Description The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism. This allows an attacker with network access to directly access and modify its configuration and operational functions without credentials. There have been reports of attackers exploiting this flaw to gain unauthenticated access, escalate privileges, and move laterally through manufacturing networks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Implement runtime segmentation to contain post-compromise activity in critical infrastructure.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-3893

Affected Products

Vasco-B Gnss Receiver