CVE-2026-18808

9.8

Klemsan Electrical Electronics · KIO (Klemsan Internet Objects)

An improper code generation vulnerability in the Klemsan KIO IoT platform allows unauthenticated remote attackers to perform code injection and achieve remote code execution.

Executive summary

A critical code injection vulnerability in Klemsan KIO versions before v1.9 exposes industrial IoT platforms to unauthenticated remote code execution.

Vulnerability

This flaw, identified as CWE-94, allows an unauthenticated remote attacker to inject and execute arbitrary code. By exploiting the improper control of code generation, an attacker can bypass security mechanisms to gain full control over the affected IoT platform.

Business impact

With a CVSS score of 9.8, this vulnerability presents a severe risk to operational technology environments. Compromise of the KIO platform could result in unauthorized control of connected industrial systems, leading to process disruption, physical safety risks, and the theft of sensitive operational data.

Remediation

Immediate Action: Upgrade Klemsan KIO to version v1.9 or later to fully remediate the code injection risk.

Proactive Monitoring: Monitor system logs for anomalous code execution or unauthorized process initiation on the KIO platform.

Compensating Controls: Isolate the KIO platform from the public internet using firewalls or VPNs to restrict access to authorized personnel only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Klemsan KIO must apply the v1.9 update immediately to prevent unauthorized code execution. Given the nature of industrial IoT systems, implementing network segmentation is strongly recommended as a secondary layer of defense against remote exploitation.

Sources

Originally found and disclosed by Yemliha İPEK, per the CVE Program record.