PT-2026-61829 · Kronosnet · Kronosnet
CVE-2026-15812
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
kronosnet versions prior to 1.35
Description
An issue exists in the internal Access Control List (ACL) subsystem. When the framework is configured to manage dynamic links to accept network traffic from any IP address without network payload encryption, the validation architecture implicitly trusts the link ID provided in incoming data packets. A remote, unauthenticated attacker can spoof a legitimate link ID within crafted network frames to bypass the ACL framework and inject arbitrary data packets into the application layer, which may result in data corruption or service instabilities.
Recommendations
Update kronosnet to a version newer than 1.34.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kronosnet