CVE-2026-25086 identifies a vulnerability in WebCTRL where a local attacker can bind to the same port used by the service. This allows the attacker to impersonate the WebCTRL service and craft malicious packets without code injection. Rated 7.7 High (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), it poses a significant risk to confidentiality and integrity with low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Automated Logic | WebCTRL Premium Server | >= 0, < v8.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.