CVE-2026-26342
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the management interface until the token is revoked, enabling unauthorized access to device functions and data.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-613
Source
NVD
Vendor
Tattile s.r.l.
Product
Smart+, Tolling+, Smart+ Speed, Smart+ Traffic Light, Axle Counter, Vega53, Vega33, Vega11, Basic MK2, ANPR Mobile
Discussion (0)
Add Comment
No comments yet. Be the first!