CVE-2026-22909
7.5SICK AG · TDC-X401GL
A lack of proper authorization in SICK AG TDC-X401GL allows unauthorized users to manipulate system applications, leading to potential service disruption.
Executive summary
An improper access control vulnerability in the SICK AG TDC-X401GL allows remote, unauthenticated attackers to disrupt system operations by managing installed applications.
Vulnerability
This vulnerability is classified as an improper access control issue (CWE-284), where system functions lack necessary authentication checks. An unauthenticated attacker can remotely trigger, stop, or delete applications on the device.
Business impact
The ability for an unauthenticated attacker to stop or delete critical applications poses a significant risk to operational continuity. This vulnerability, carrying a CVSS score of 7.5, represents a high-severity threat to availability, which could lead to unplanned downtime and loss of control over industrial processes.
Remediation
Immediate Action: Consult the official SICK AG PSIRT portal for available security bulletins, as no specific patch version is currently identified. If a firmware update is not yet available, restrict network access to the device to trusted management segments only.
Proactive Monitoring: Review system and access logs for unauthorized attempts to invoke management functions or unexpected application state changes. Monitor network traffic for unusual requests directed at the device administrative interfaces.
Compensating Controls: Deploy a firewall or network access control list (ACL) to ensure that the TDC-X401GL is not accessible from untrusted networks or the public internet.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete service disruption, this vulnerability requires immediate attention. Organizations should prioritize isolating affected TDC-X401GL units from external networks and coordinate with SICK AG support to determine the timeline for a permanent firmware fix.