Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-10577: Rockwell Automation 1715 Redundant IO - Unsecured Debug Port Exposes Device to Hackers

CVE-2026-10577 CVE-2026-10577
Summary

An unsecured port on Rockwell Automation's 1715 Redundant IO device allows hackers to access sensitive commands remotely. This could lead to data loss, system crashes, or unauthorized changes to the device's settings. To protect your device, ensure the debug port is disabled or properly secured.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rockwell auotmation 1715 ethernet/ip communications module 3.003 and prior
Original title
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthentic...
Original description
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.
nvd CVSS4.0 10.0
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026