CVE-2026-103548

Summary

Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.

Affected Software

VendorProductVersion RangeStatus
ItronMV-90 xi3.0affected

Weaknesses

  • CWE-257: CWE-257 Storing passwords in a recoverable format
  • CWE-260: CWE-260 Password in configuration file
  • CWE-261: CWE-261 Weak encoding for password

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References