Tattile manufactures industrial automation and transportation-monitoring devices, including ANPR systems, axle counters, and control units, where vulnerabilities center on authentication and session-management weaknesses such as default credentials, missing authentication for critical functions, and insufficient session expiration. These patterns reflect the legacy authentication posture and constrained firmware environments typical of specialized industrial equipment deployed in field conditions. Current exposure counts and severity data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tattile over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26341CRITICAL Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissio | Feb 24, 2026 | 9.8 | 45 | NO | YES |
CVE-2026-26342CRITICAL Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who o | Feb 24, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-26340HIGH Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP | Feb 24, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tattile.
Media articles that mention a CVE ID that affects a product developed by Tattile — matched by CVE ID, not by vendor name.