CVE Explorer
CVE-2026-26333
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with TypeFilterLevel set to Full. An unauthenticated remote attacker can invoke the exposed remoting endpoints to perform arbitrary file read and write operations via the WebClient class. This allows retrieval of sensitive files such as
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"VeraSMART","vendor":"Calero","versions":[{"lessThan":"2022 R1","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":10,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"tags":["product"],"url":"https://www.calero.com/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/references/0
{"tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/calero-verasmart-2022-r1-net-remoting-arbitrary-file-read-leading-to-viewstate-rce"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8f2708d334ef7b3f3c70589cba7d4cb684006fb0d0716948ce86d8334a3605eb · sha256:764ee91a7ffdf89a… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.