← Vulnerability feed

Vulnerability record · CVE-2026-22910 · published 15 January 2026

CVE-2026-22910: Sick tdc-x401gl firmware vulnerability

Sick · Tdc X401gl Firmware

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

9.1 CVSS 3.1 Critical EPSS 0.48% · top 61.0% CWE-1391 · CWE-1391
9.1CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22910 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-22907Sick tdc-x401gl firmware vulnerabilityAn attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.EPSS 0.45%9.1CVE-2026-22908Sick tdc-x401gl firmware vulnerabilityUploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confi…EPSS 0.60%9.1CVE-2026-22909Sick tdc-x401gl firmware improper access control vulnerabilityCertain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential…EPSS 0.56%8.2CVE-2026-22918Sick tdc-x401gl firmware clickjacking vulnerabilityAn attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web …EPSS 0.32%7.5CVE-2026-22917Sick tdc-x401gl firmware allocation without limits vulnerabilityImproper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.EPSS 0.56%7.5CVE-2026-22911Sick tdc-x401gl firmware hard-coded credentials vulnerabilityFirmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorize…EPSS 0.53%6.5CVE-2026-22914Sick tdc-x401gl firmware vulnerabilityAn attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.EPSS 0.31%6.5CVE-2026-22915Sick tdc-x401gl firmware vulnerabilityAn attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2026-22910), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.