← Vulnerability feed

Vulnerability record · CVE-2016-2296 · published 14 May 2016

CVE-2016-2296: Meteocontrol WEB'log post-admin pages lack authentication

Meteocontrol · Web\'Log Basic 100

Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited do not require authentication for "post-admin" login pages, exposing administrative functionality to anyone who can reach the device. Because these are internet-facing or network-reachable monitoring devices, unauthenticated access to admin pages lets attackers read sensitive data or alter device configuration.

9.4 CVSS 3.0 Critical EPSS 64% · top 0.8% CWE-254 · CWE-254
9.4CVSS 3.0 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 3.0 base score is 9.4 (critical) with network reachability, no authentication, and high confidentiality and integrity impact, and public exploit code exists.

What it is

Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited do not require authentication for "post-admin" login pages, exposing administrative functionality to anyone who can reach the device. Because these are internet-facing or network-reachable monitoring devices, unauthenticated access to admin pages lets attackers read sensitive data or alter device configuration.

Impact

An attacker gains unauthenticated read and write access to administrative functionality, allowing disclosure of sensitive information and modification of device data or settings.

Attack surface

Reachable over the network (CVSS vector AV:N) with no privileges (PR:N) and no user interaction (UI:N); the flaw is in the device's own login handling, so no credentials are needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.6426 (99.2nd percentile) and public references include an Exploit-DB entry, indicating exploit code is publicly available.

What to do

  • Apply the vendor fix or the mitigations in ICS-CERT advisory ICSA-16-133-01; patch is the first action.
  • Remove direct internet exposure of WEB'log devices and place them behind a firewall or VPN with access restricted to trusted management hosts.
  • Enforce authentication at a reverse proxy or gateway in front of the device if the device itself cannot be fixed.
  • Monitor and restrict network access to the admin/post-admin paths to known administrative IPs only.
  • Rotate any credentials or data that may have been exposed through unauthenticated admin access.

Detection

  • Review web server or device logs for requests to post-admin login pages from unexpected or external source IPs.
  • Alert on access to administrative URLs without a preceding successful authentication event.
  • Baseline normal management source IPs and flag admin-page access from outside that set.
  • Watch for configuration changes or data reads on WEB'log devices that cannot be tied to a legitimate admin session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2296 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2016-2296), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.