CVE-2026-4832 is a hard-coded credentials vulnerability (CWE-798) affecting device SNMP ports that permits unauthenticated attackers to access sensitive device information without proper authentication. The vulnerability exists in network devices that expose SNMP services with embedded credentials, allowing remote interrogation of the affected systems. The attack vector is network-based with likely low complexity, as exploitation requires only SNMP port access without authentication barriers. The potential impact includes unauthorized disclosure of sensitive device configuration and operational data, though the vulnerability does not appear to enable system compromise or lateral movement based on available information. Current exploitation status indicates this vulnerability is not actively exploited in the wild, with no known public exploit code readily available. The CVE is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention remains minimal, suggesting limited real-world threat activity at this time. However, the FAUCET risk score of 46.0 indicates moderate concern warranting remediation through credential rotation and SNMP access restrictions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Schneider Electric | Easergy MiCOM P14x | All versions prior to B4ACNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM P24x | All versions prior to D3ACNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM P341 | All versions prior to E3FCNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM P342, P343, P344, P345 | All versions prior to B3FCNA affecteddefault unaffected | |
| Schneider Electric | Easergy MiCOM P442, P444 | All versions prior to E3ACNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.