DEV Community

threataft
threataft

Posted on Originally published at threataft.com

CVE-2026-94293: AAS Edge Client — CVSS 9.8 IIoT Data Tampering, No Patch, Decommission Now

CVE-2026-94293 (CVSS 9.8) — Murrelektronik's Software AAS Edge Client exposes an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read all AAS submodel data via GET and overwrite it via PATCH — no credentials, no user interaction, no exploit code required.
Modified data propagates to central AAS servers, extending impact downstream. CORS is unrestricted, so browser-based attacks work too.
No patch. Vendor has archived the repositories and recommends decommissioning.
The practical risk: this was a trade-fair demonstrator, so it may be running in environments where it was never formally inventoried. Check containers and edge deployments.
Full analysis → https://threataft.com/articles/aas-edge-client-cve-2026-94293

Top comments (0)