by WebCTRL. This could allow the attacker to craft and send malicious
packets and impersonate the WebCTRL service without requiring code
injection into the WebCTRL software.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Automated Logic notes that WebCTRL 7 is end of life and has been out of support since January 27, 2023. Users are advised to upgrade to the latest version of the WebCTRL server application, which supports the more secure BACnet/SC.
Workaround
No workaround given by the vendor.
Sat, 21 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software. | |
| Title | Automated Logic WebCTRL Premium Server Multiple Binds to the Same Port | |
| Weaknesses | CWE-605 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-03-20T23:15:23.243Z
Reserved: 2026-03-12T19:57:03.300Z
Link: CVE-2026-25086
No data.
Status : Received
Published: 2026-03-21T00:16:25.683
Modified: 2026-03-21T00:16:25.683
Link: CVE-2026-25086
No data.
OpenCVE Enrichment
No data.