CVE-2026-3356
The MS27102A Remote Spectrum Monitor has a design flaw that lets anyone access its management interface without authentication. Because the device never offers a way to enable login, attackers can read or change settings freely. This flaw is critical because it gives full control over the device.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
MS27102A Remote Spectrum Monitor devices (used in wireless spectrum monitoring).
Real-world impact
An attacker who can reach the device can view and modify its configuration, potentially disrupting spectrum monitoring, redirecting traffic, or using the device for malicious purposes.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability has high confidentiality, integrity, and availability impact, requires no authentication, and can be exploited remotely with no user interaction.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Mar 31, 2026 · Mar 31, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.