CVE Explorer
CVE-2026-9650
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller","vendor":"Schneider Electric","versions":[{"status":"affected","version":"Version 11.06.30 and prior"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"Saitel DP Remote Terminal Unit & Controller","vendor":"Schneider Electric","versions":[{"status":"affected","version":"Version 11.06.35 and prior"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller","vendor":"Schneider Electric","versions":[{"status":"affected","version":"Version 11.06.30 and prior"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"Saitel DP Remote Terminal Unit & Controller","vendor":"Schneider Electric","versions":[{"status":"affected","version":"Version 11.06.35 and prior"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-522","description":"CWE-522 Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-02.pdf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dbb7e528a04c741b4f0566689011dad4030bdf94520ed1fa00b7e68b4273de4d · sha256:3dfff9c786b3b7db… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.