CVE-2026-3356 describes a critical authentication bypass vulnerability in the MS27102A Remote Spectrum Monitor, stemming from an inherent design flaw that allows unauthorized network users to access and manipulate its management interface. Rated 9.3 CRITICAL, this vulnerability has a low attack complexity and can lead to complete compromise of the device's confidentiality, integrity, and availability. While there is currently no evidence of active exploitation or publicly available exploit code, the issue has garnered some community attention, including a CISA alert and mentions on social media.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Anritsu | Remote Spectrum Monitor MS27100A | All versionsCNA affecteddefault unaffected | |
| Anritsu | Remote Spectrum Monitor MS27101A | All versionsCNA affecteddefault unaffected | |
| Anritsu | Remote Spectrum Monitor MS27102A | All versionsCNA affecteddefault unaffected | |
| Anritsu | Remote Spectrum Monitor MS27103A | All versionsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.