CVE-2026-22910

7.5

SICK AG · TDC-X401GL

SICK AG TDC-X401GL devices contain weak and publicly known default credentials for hidden user levels, which can allow unauthorized access to the system.

Executive summary

The SICK AG TDC-X401GL series is vulnerable to unauthorized access due to the presence of hardcoded default credentials, posing a significant risk to industrial control system integrity.

Vulnerability

This vulnerability involves the use of weak and publicly known default passwords for hidden administrative or service-level accounts. The vulnerability is exploitable by an unauthenticated remote attacker with network access to the device.

Business impact

Successful exploitation of this flaw allows an attacker to gain unauthorized access to sensitive device functions, potentially leading to unauthorized configuration changes or the compromise of operational data. Given the CVSS score of 7.5, this high-severity vulnerability represents a substantial risk to the availability and integrity of operational technology environments where these devices are deployed.

Remediation

Immediate Action: Consult the official SICK PSIRT advisory for instructions on changing default passwords or disabling affected hidden user accounts. If a firmware update is unavailable, ensure the device is not accessible from the public internet.

Proactive Monitoring: Review device access logs for frequent or suspicious login attempts, particularly those originating from unauthorized network segments or occurring outside of standard maintenance windows.

Compensating Controls: Deploy the device behind a robust firewall or within a segmented industrial network to restrict access to authorized personnel only, effectively mitigating the risk of remote exploitation.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Organizations utilizing SICK AG TDC-X401GL hardware must prioritize the identification and hardening of these devices. Because the vulnerability involves default credentials, the risk can be effectively neutralized by enforcing strong, unique password policies or restricting network access to the management interface immediately. Failure to address this could lead to full unauthorized control of the affected industrial hardware.

Sources