CVE-2026-94293 (CVSS 9.8) — Murrelektronik's Software AAS Edge Client exposes an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read all AAS submodel data via GET and overwrite it via PATCH — no credentials, no user interaction, no exploit code required.
Modified data propagates to central AAS servers, extending impact downstream. CORS is unrestricted, so browser-based attacks work too.
No patch. Vendor has archived the repositories and recommends decommissioning.
The practical risk: this was a trade-fair demonstrator, so it may be running in environments where it was never formally inventoried. Check containers and edge deployments.
Full analysis → https://threataft.com/articles/aas-edge-client-cve-2026-94293
For further actions, you may consider blocking this person and/or reporting abuse
Top comments (0)