CVE-2026-32962 is a missing authentication vulnerability affecting Silex Technology's SD-330AC and AMC Manager products that allows unauthorized modification of device configuration. An unauthenticated remote attacker can alter critical device settings without providing credentials, posing a significant integrity risk. The vulnerability has been assigned a CVSS score of 5.3 (Medium severity) with a network-based attack vector requiring low complexity. Exploitation status indicates minimal current threat activity, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The FAUCET risk score of 32.0/100 and low EPSS value suggest this remains a low-priority threat from a community attention perspective, though organizations running affected devices should implement access controls and configuration management strategies as a precautionary measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.