CVE-2026-14837

Summary

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.

Affected Software

VendorProductVersion RangeStatus
Lenzec4301.0.0 < 1.15.2affected
Lenzec5201.0.0 < 1.15.2affected
Lenzec5501.0.0 < 1.15.2affected
Lenzei950 GenA1.0.0 < 1.14.2affected
Lenzei950 GenB2.0.0 < 2.0.3affected

Weaknesses

  • CWE-347: CWE-347 Improper Verification of Cryptographic Signature

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References