CVE-2026-32965 is an initialization vulnerability affecting Silex Technology's SD-330AC and AMC Manager devices that allows them to be configured with a null string (blank) password when deployed with factory-default settings. This insecure default configuration creates an authentication bypass condition for networked instances of these products. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector that requires no authentication or user interaction, indicating it can be exploited remotely by unauthenticated threat actors. While the vulnerability does not compromise confidentiality or availability, it enables high-impact integrity violations through unauthorized device configuration. There is currently no evidence of active exploitation in the wild, as the vulnerability is not included on CISA's Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.00029 indicates this threat ranks below average in terms of real-world exploitation probability relative to other disclosed vulnerabilities, though organizations running these devices should still prioritize remediation by changing default credentials immediately upon deployment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.50CPE matchmatch criteria | cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.