HIGH · 7.5

CVE-2026-9650

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within f...

Vulnerability Description

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Schneider-ElectricEasylogic T150 Firmware< 11.06.32
Schneider-ElectricEasylogic T150-
Schneider-ElectricSaitel Dp Firmware< 11.06.38
Schneider-ElectricSaitel Dp-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-9650?

CVE-2026-9650 is a vulnerability with a CVSS score of 7.5 (HIGH). CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within f...

How severe is CVE-2026-9650?

CVE-2026-9650 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-9650?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Easylogic T150 Firmware, Schneider-Electric Easylogic T150, Schneider-Electric Saitel Dp Firmware, Schneider-Electric Saitel Dp.