Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-077/ |
|
History
Mon, 27 Jul 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise. | |
| Title | SSH Enablement Signature Verification Bypass | |
| First Time appeared |
Lenze
Lenze c4xx Firmware Lenze c5xx Firmware Lenze i950 Firmware |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:o:lenze:c4xx_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenze:c5xx_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:lenze:i950_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenze
Lenze c4xx Firmware Lenze c5xx Firmware Lenze i950 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-27T07:03:27.889Z
Reserved: 2026-07-06T09:59:37.390Z
Link: CVE-2026-14837
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses