AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-2330

CRITICAL · CVSS 9.4 EPSS 0.66%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-03-06 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.4. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-2330
Severity
CRITICAL
CVSS
9.4
EPSS
0.66%

Original NVD Description

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters.