CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-26689

CVSS 9.8v3.1pub. 2025-03-31upd. 2026-04-15

Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.

🤖 AI Analysis
How it works

The vulnerability of the CWE-425 class (Direct Request / Forced Browsing) consists of the lack of proper permission verification for direct HTTP requests to device resources. An attacker can bypass access control mechanisms by sending crafted HTTP requests directly to protected resources or API endpoints. No authentication or user interaction is required, and the attack is possible remotely over the network.

Impact

An attacker can gain access to data collected by the production line monitoring device, delete this data, or modify device settings, which may disrupt monitoring and event logging processes in an industrial environment.

Mitigation & patch

The manufacturer (INABA) has not indicated an available patched version in the description. Patches available from the manufacturer should be applied according to the references. It is also recommended to restrict network access to the device through isolation in the OT/ICS network, use firewalls, and avoid direct exposure of the device to the internet.

Who is affected

CHOCO TEI WATCHER mini (IB-MCT001) — all software versions

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References